2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2014-125045CRITICAL9.8A vulnerability has been found in meol1 and classified as critical. Affected by this vulnerability is the function GetAn...
CVE-2014-125044CRITICAL9.8A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of t...
CVE-2014-125041CRITICAL9.8A vulnerability classified as critical was found in Miccighel PR-CWT. This vulnerability affects unknown code. The manip...
CVE-2014-125040CRITICAL9.8A vulnerability was found in stevejagodzinski DevNewsAggregator. It has been rated as critical. Affected by this issue i...
CVE-2014-125038CRITICAL9.8A vulnerability has been found in IS_Projecto2 and classified as critical. This vulnerability affects unknown code of th...
CVE-2014-125037CRITICAL9.8A vulnerability, which was classified as critical, was found in License to Kill. This affects an unknown part of the fil...
CVE-2014-125032CRITICAL9.8A vulnerability was found in porpeeranut go-with-me. It has been declared as critical. Affected by this vulnerability is...
CVE-2014-125030CRITICAL9.8A vulnerability, which was classified as critical, has been found in taoeffect Empress. Affected by this issue is some u...
CVE-2014-125026CRITICAL9.8LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code executio...
CVE-2014-8164CRITICAL9.1A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verific...
CVE-2014-0156CRITICAL9.8Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Aweso...
CVE-2014-9320CRITICAL9.8SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and conse...
CVE-2014-8945CRITICAL9.8admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
CVE-2014-8941CRITICAL9.8Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= U...
CVE-2014-7175CRITICAL9.8FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.
CVE-2014-7173CRITICAL9.8FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx2...
CVE-2014-1634CRITICAL9.8SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subsc...
CVE-2014-4650CRITICAL9.8The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path ...
CVE-2014-4657CRITICAL9.8The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers...
CVE-2014-3484CRITICAL9.8Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 ...
CVE-2014-4678CRITICAL9.8The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers...
CVE-2014-9614CRITICAL9.8The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it eas...
CVE-2014-9613CRITICAL9.8Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co...
CVE-2014-9612CRITICAL9.8SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1...
CVE-2014-2727CRITICAL9.8The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now