2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9618The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att...
CVE-2014-9616Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive informa...
CVE-2014-9611Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via ...
CVE-2014-9610Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an...
CVE-2014-8174eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
CVE-2014-6191Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote ...
CVE-2014-5362The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion...
CVE-2014-6106Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attacke...
CVE-2014-9463functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v...
CVE-2014-9635Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41...
CVE-2014-9634Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it ...
CVE-2014-9624CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
CVE-2014-9565Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switc...
CVE-2014-6438The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service ...
CVE-2014-8677The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and...
CVE-2014-8676Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke...
CVE-2014-8675Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all...
CVE-2014-9497Buffer overflow in mpg123 before 1.18.0.
CVE-2014-8872Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after...
CVE-2014-8393DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel...
CVE-2014-8163Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
CVE-2014-9558Multiple SQL injection vulnerabilities in SmartCMS v.2.
CVE-2014-9514Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.
CVE-2014-9513Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
CVE-2014-9483Emacs 24.4 allows remote attackers to bypass security restrictions.

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now