2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-0363The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints...
CVE-2014-0114Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o...
CVE-2014-2853Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before...
CVE-2014-0088The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platf...
CVE-2014-2185The Call Detail Records (CDR) Management component in Cisco Unified Communications Manager (Unified CM) allows remote au...
CVE-2014-2184The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers t...
CVE-2014-2183The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a d...
CVE-2014-2182Cisco Adaptive Security Appliance (ASA) Software, when DHCPv6 replay is configured, allows remote attackers to cause a d...
CVE-2014-2180The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which ...
CVE-2014-1843Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke...
CVE-2014-1842Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke...
CVE-2014-1841Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke...
CVE-2014-0515Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS ...
CVE-2014-0113CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict ...
CVE-2014-0112ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all...
CVE-2014-3008Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacte...
CVE-2014-2986The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen ...
CVE-2014-2980Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file ...
CVE-2014-2846Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmw...
CVE-2014-2715Multiple cross-site scripting (XSS) vulnerabilities in vwrooms\templates\logout.tpl.php in the VideoWhisper Webcam plugi...
CVE-2014-2658Unspecified vulnerability in Papercut MF and NG before 14.1 (Build 26983) allows attacker to cause a denial of service v...
CVE-2014-2657Unspecified vulnerability in the print release functionality in PaperCut MF before 14.1 (Build 26983) has unknown impact...
CVE-2014-2383dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo...
CVE-2014-2042Unrestricted file upload vulnerability in the Manage Project functionality in Livetecs Timelive before 6.5.1 allows remo...
CVE-2014-1217Livetecs Timelive before 6.2.8 does not properly restrict access to systemsetting.aspx, which allows remote attackers to...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now