2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5394 | — | — | 1.7% | Jan 8, 2018 | Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the ma... |
| CVE-2014-5334 | — | — | 5.1% | Jan 8, 2018 | FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a ... |
| CVE-2014-5071 | CRITICAL | 9.8 | 1.7% | Jan 8, 2018 | SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execut... |
| CVE-2014-5069 | MEDIUM | 6.1 | 1.0% | Jan 8, 2018 | Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15 allows remote attackers to inject arbitrary web sc... |
| CVE-2014-4972 | — | — | 4.7% | Jan 8, 2018 | Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote att... |
| CVE-2014-3607 | — | — | 0.9% | Jan 8, 2018 | DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domai... |
| CVE-2014-2071 | — | — | 0.6% | Jan 8, 2018 | Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to... |
| CVE-2014-1859 | — | — | 0.5% | Jan 8, 2018 | (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in Nu... |
| CVE-2014-1858 | — | — | 0.4% | Jan 8, 2018 | __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a tempo... |
| CVE-2014-10069 | — | — | 4.0% | Jan 7, 2018 | Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which ... |
| CVE-2014-8579 | — | — | 2.0% | Jan 5, 2018 | TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account,... |
| CVE-2014-8540 | — | — | 2.2% | Jan 5, 2018 | The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitra... |
| CVE-2014-8336 | — | — | 2.6% | Jan 5, 2018 | The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attacke... |
| CVE-2014-8335 | — | — | 0.5% | Jan 5, 2018 | (1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for Word... |
| CVE-2014-7862 | — | — | 81.0% | Jan 4, 2018 | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at... |
| CVE-2014-9515 | CRITICAL | 9.8 | 5.6% | Dec 29, 2017 | Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbi... |
| CVE-2014-8119 | — | — | 2.7% | Dec 29, 2017 | The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash... |
| CVE-2014-4978 | — | — | 0.4% | Dec 29, 2017 | The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary file... |
| CVE-2014-3630 | — | — | 2.8% | Dec 29, 2017 | XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2... |
| CVE-2014-0121 | — | — | 3.9% | Dec 29, 2017 | The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary comman... |
| CVE-2014-0120 | — | — | 1.2% | Dec 29, 2017 | Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the a... |
| CVE-2014-3651 | — | — | 1.6% | Dec 29, 2017 | JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a larg... |
| CVE-2014-4914 | — | — | 2.3% | Dec 29, 2017 | The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows re... |
| CVE-2014-8389 | — | — | 50.5% | Dec 28, 2017 | cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.... |
| CVE-2014-8358 | — | — | 5.0% | Dec 11, 2017 | Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014)... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now