2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9618——The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att...
CVE-2014-9616——Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive informa...
CVE-2014-9611——Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via ...
CVE-2014-9610——Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an...
CVE-2014-8174——eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
CVE-2014-6191——Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote ...
CVE-2014-5362——The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion...
CVE-2014-6106——Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attacke...
CVE-2014-9463——functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v...
CVE-2014-9635——Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41...
CVE-2014-9634——Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it ...
CVE-2014-9624——CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
CVE-2014-9565——Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switc...
CVE-2014-6438——The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service ...
CVE-2014-8677——The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and...
CVE-2014-8676——Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke...
CVE-2014-8675——Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all...
CVE-2014-9497——Buffer overflow in mpg123 before 1.18.0.
CVE-2014-8872——Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after...
CVE-2014-8393——DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel...
CVE-2014-8163——Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
CVE-2014-9558——Multiple SQL injection vulnerabilities in SmartCMS v.2.
CVE-2014-9514——Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.
CVE-2014-9513——Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
CVE-2014-9483——Emacs 24.4 allows remote attackers to bypass security restrictions.

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now