2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-2051ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via uns...
CVE-2014-3963ownCloud Server before 6.0.1 does not properly check permissions, which allows remote authenticated users to access arbi...
CVE-2014-3962Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via t...
CVE-2014-3961SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allo...
CVE-2014-3960Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.12.7 allow remote attackers to inject arbitrary ...
CVE-2014-3949Cross-site scripting (XSS) vulnerability in the layout wizard in the Grid Elements (gridelements) extension before 1.5.1...
CVE-2014-3948Cross-site scripting (XSS) vulnerability in the HTML export wizard in the backend module in the powermail extension befo...
CVE-2014-3913Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrar...
CVE-2014-3838ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not properly check permissions, which allows remote authentica...
CVE-2014-3837The document application in ownCloud Server before 6.0.3 uses sequential values for the file_id, which allows remote aut...
CVE-2014-3836Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud Server before 6.0.3 allow remote attackers to hij...
CVE-2014-3835ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not check permissions to the files_external application, which...
CVE-2014-3834ownCloud Server before 6.0.3 does not properly check permissions, which allows remote authenticated users to (1) access ...
CVE-2014-3833Multiple cross-site scripting (XSS) vulnerabilities in the (1) Gallery and (2) core components in ownCloud Server before...
CVE-2014-3832Cross-site scripting (XSS) vulnerability in the Documents component in ownCloud Server 6.0.x before 6.0.3 allows remote ...
CVE-2014-3786Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 ...
CVE-2014-2056PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary file...
CVE-2014-2055SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read...
CVE-2014-2054PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity...
CVE-2014-2053getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read ...
CVE-2014-3956The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently ski...
CVE-2014-0935Unspecified vulnerability in IBM Smart Analytics System 7700 before FP 2.1.3.0 and 7710 before FP 2.1.3.0 allows local u...
CVE-2014-2502Cross-site scripting (XSS) vulnerability in rsa_fso.swf in EMC RSA Adaptive Authentication (Hosted) 11.0 allows remote a...
CVE-2014-3959Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM,...
CVE-2014-3946The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validat...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now