2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3279The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and ear...
CVE-2014-3277The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and ear...
CVE-2014-3417uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to config...
CVE-2014-3416uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manag...
CVE-2014-3415SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL command...
CVE-2014-3414Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authenti...
CVE-2014-0246SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitiv...
CVE-2014-0201ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, use...
CVE-2014-0200The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permiss...
CVE-2014-0199The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) packa...
CVE-2014-0239The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS ...
CVE-2014-0178Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is...
CVE-2014-0240The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by...
CVE-2014-0177The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlin...
CVE-2014-3872Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 ...
CVE-2014-3871Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds ...
CVE-2014-3870Cross-site scripting (XSS) vulnerability in the bib2html plugin 0.9.3 for WordPress allows remote attackers to inject ar...
CVE-2014-3840Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.1...
CVE-2014-2720IZArc 4.1.8 displays a file's name on the basis of a ZIP archive's Central Directory entry, but launches this file on th...
CVE-2014-0218Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2....
CVE-2014-0217enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before li...
CVE-2014-0216The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x ...
CVE-2014-0215The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6...
CVE-2014-0214login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a Mood...
CVE-2014-0213Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moo...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now