2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3114The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to e...
CVE-2014-2078The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive informatio...
CVE-2014-2073CRITICAL9.8Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a...
CVE-2014-1946OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypa...
CVE-2014-1889The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain...
CVE-2014-1400The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users ...
CVE-2014-1399The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate...
CVE-2014-1398The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate...
CVE-2014-0158Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause ...
CVE-2014-1226The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permission...
CVE-2014-5072Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote...
CVE-2014-5034Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remo...
CVE-2014-3539CRITICAL9.8base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveragi...
CVE-2014-2359OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or s...
CVE-2014-3413The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, w...
CVE-2014-9959An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9958An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9957An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9956An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9955An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9954An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9953An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-6604Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress ...
CVE-2014-5170The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveragin...
CVE-2014-5028The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote aut...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now