2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-7198OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protecti...
CVE-2014-5401Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform soft...
CVE-2014-5433An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored ...
CVE-2014-5432Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is rem...
CVE-2014-5431Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contai...
CVE-2014-5434Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a ...
CVE-2014-9189Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, ...
CVE-2014-9187Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all ve...
CVE-2014-10079In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hid...
CVE-2014-10078Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfa...
CVE-2014-1000000Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2014-10077Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial ...
CVE-2014-10076The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier ...
CVE-2014-10075The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
CVE-2014-6050phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
CVE-2014-6049phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted ins...
CVE-2014-6048phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
CVE-2014-6047phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever...
CVE-2014-6046Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack th...
CVE-2014-6045SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to exec...
CVE-2014-4932Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attac...
CVE-2014-10074Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release...
CVE-2014-4150The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via ...
CVE-2014-2296XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 an...
CVE-2014-2302The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now