2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6607 | — | — | 6.6% | Oct 6, 2014 | M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers... |
| CVE-2014-6409 | — | — | 2.3% | Oct 6, 2014 | Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authe... |
| CVE-2014-6389 | — | — | 8.6% | Oct 6, 2014 | backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharact... |
| CVE-2014-4510 | — | — | 1.0% | Oct 6, 2014 | Cross-site scripting (XSS) vulnerability in job.cc in apt-cacher-ng 0.7.26 allows remote attackers to inject arbitrary w... |
| CVE-2014-4043 | — | — | 3.9% | Oct 6, 2014 | The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with th... |
| CVE-2014-2044 | — | — | 12.4% | Oct 6, 2014 | Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut... |
| CVE-2014-1875 | — | — | 0.5% | Oct 6, 2014 | The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a t... |
| CVE-2014-1868 | — | — | 1.3% | Oct 6, 2014 | Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows a... |
| CVE-2014-1224 | — | — | 1.2% | Oct 6, 2014 | Incomplete blacklist vulnerability in the user registration feature in rexx Recruitment R6.1 and R7 without "fixes from ... |
| CVE-2014-0397 | — | — | 2.2% | Oct 6, 2014 | Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impact and attack vector... |
| CVE-2014-7870 | — | — | 0.9% | Oct 6, 2014 | Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14... |
| CVE-2014-7869 | — | — | 0.9% | Oct 6, 2014 | Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.... |
| CVE-2014-6054 | — | — | 5.5% | Oct 6, 2014 | The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote a... |
| CVE-2014-5389 | — | — | 2.3% | Oct 6, 2014 | SQL injection vulnerability in content-audit-schedule.php in the Content Audit plugin before 1.6.1 for WordPress allows ... |
| CVE-2014-3657 | — | — | 2.8% | Oct 6, 2014 | The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list ... |
| CVE-2014-3642 | — | — | 1.3% | Oct 6, 2014 | vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3... |
| CVE-2014-3633 | — | — | 2.8% | Oct 6, 2014 | The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or... |
| CVE-2014-3608 | — | — | 1.7% | Oct 6, 2014 | The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limi... |
| CVE-2014-3521 | — | — | 1.4% | Oct 6, 2014 | The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users... |
| CVE-2014-0994 | — | — | 2.8% | Oct 6, 2014 | Heap-based buffer overflow in the ReadDIB function in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Comp... |
| CVE-2014-0168 | — | — | 0.7% | Oct 6, 2014 | Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentica... |
| CVE-2014-0140 | — | — | 1.2% | Oct 6, 2014 | Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive control... |
| CVE-2014-0074 | — | — | 5.5% | Oct 6, 2014 | Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to b... |
| CVE-2014-2644 | — | — | 3.1% | Oct 6, 2014 | Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to injec... |
| CVE-2014-7861 | — | — | 2.4% | Oct 5, 2014 | The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attack... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now