2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-8293Cross-site scripting (XSS) vulnerability in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to inject arbitrary w...
CVE-2014-7206The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the c...
CVE-2014-6312Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before ...
CVE-2014-3681Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to injec...
CVE-2014-3664Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with ...
CVE-2014-3593Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitr...
CVE-2014-2927The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before...
CVE-2014-2576plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name field...
CVE-2014-2022SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier a...
CVE-2014-1830Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-A...
CVE-2014-1829Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorizatio...
CVE-2014-6952The Manga Facts (aka app.mangafacts.ar) application 1.0 for Android does not verify X.509 certificates from SSL servers,...
CVE-2014-6951The OneFile Ignite (aka uk.co.onefile.ignite) application 1.19 for Android does not verify X.509 certificates from SSL s...
CVE-2014-6950The Mt. Airy News (aka com.soln.SBE4A803AD6430A6E9DBA5688AA644148) application 1.0069.b0069 for Android does not verify ...
CVE-2014-6949The Akne Ernahrung (aka com.rareartifact.akneernahrung72010074) application 1.0 for Android does not verify X.509 certif...
CVE-2014-6948The TH3 professional Al Mohtarif (aka com.th3professional.almohtarif) application 1.0 for Android does not verify X.509 ...
CVE-2014-6947The Archie Comics (aka com.iversecomics.archie.android) application 1.07 for Android does not verify X.509 certificates ...
CVE-2014-6946The Re:kyu (aka com.appzone619) application 1.0 for Android does not verify X.509 certificates from SSL servers, which a...
CVE-2014-6945The Neeku Naaku Dash Dash (aka com.dakshaa.nndd) application 1.0 for Android does not verify X.509 certificates from SSL...
CVE-2014-6944The mitfahrgelegenheit.at (aka com.carpooling.android.at) application 2.3.0 for Android does not verify X.509 certificat...
CVE-2014-6943The Konigsleiten (aka com.knigsleiten) application 1.0 for Android does not verify X.509 certificates from SSL servers, ...
CVE-2014-6942The Alisha Marie (Unofficial) (aka com.automon.ay.alisha.marie) application 1.4.0.6 for Android does not verify X.509 ce...
CVE-2014-4148HIGH8.8win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a...
CVE-2014-4141Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ...
CVE-2014-4140Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted w...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now