2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-4524Cross-site scripting (XSS) vulnerability in classes/custom-image/media.php in the WP Easy Post Types plugin before 1.4.4...
CVE-2014-4522Cross-site scripting (XSS) vulnerability in client-assist.php in the dsSearchAgent: WordPress Edition plugin 1.0-beta10 ...
CVE-2014-3890silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity out...
CVE-2014-3889silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity out...
CVE-2014-4696Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attac...
CVE-2014-4695Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attacke...
CVE-2014-4694Multiple cross-site scripting (XSS) vulnerabilities in suricata_select_alias.php in the Suricata package before 1.0.6 fo...
CVE-2014-4693Multiple cross-site scripting (XSS) vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow r...
CVE-2014-4692pfSense before 2.1.4, when HTTP is used, does not include the HTTPOnly flag in a Set-Cookie header for the session cooki...
CVE-2014-4691Session fixation vulnerability in pfSense before 2.1.4 allows remote attackers to hijack web sessions via a firewall log...
CVE-2014-4690Multiple directory traversal vulnerabilities in pfSense before 2.1.4 allow (1) remote attackers to read arbitrary .info ...
CVE-2014-4689Absolute path traversal vulnerability in pkg_edit.php in pfSense before 2.1.4 allows remote attackers to read arbitrary ...
CVE-2014-4688pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_...
CVE-2014-4687Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.1.4 allow remote attackers to inject arbitrary w...
CVE-2014-3307The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to ...
CVE-2014-3298Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which al...
CVE-2014-3297Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action...
CVE-2014-3074The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and co...
CVE-2014-3066IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containin...
CVE-2014-4668The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does ...
CVE-2014-3100Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 al...
CVE-2014-3088stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenFor...
CVE-2014-3494kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning...
CVE-2014-3492Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1...
CVE-2014-3491Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to injec...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now