2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-7198——OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protecti...
CVE-2014-5401——Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform soft...
CVE-2014-5433——An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored ...
CVE-2014-5432——Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is rem...
CVE-2014-5431——Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contai...
CVE-2014-5434——Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a ...
CVE-2014-9189——Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, ...
CVE-2014-9187——Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all ve...
CVE-2014-10079——In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hid...
CVE-2014-10078——Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfa...
CVE-2014-1000000——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2014-10077——Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial ...
CVE-2014-10076——The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier ...
CVE-2014-10075——The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
CVE-2014-6050——phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
CVE-2014-6049——phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted ins...
CVE-2014-6048——phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
CVE-2014-6047——phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever...
CVE-2014-6046——Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack th...
CVE-2014-6045——SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to exec...
CVE-2014-4932——Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attac...
CVE-2014-10074——Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release...
CVE-2014-4150——The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via ...
CVE-2014-2296——XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 an...
CVE-2014-2302——The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now