2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-5394Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the ma...
CVE-2014-5334FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a ...
CVE-2014-5071CRITICAL9.8SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execut...
CVE-2014-5069MEDIUM6.1Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15 allows remote attackers to inject arbitrary web sc...
CVE-2014-4972Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote att...
CVE-2014-3607DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domai...
CVE-2014-2071Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to...
CVE-2014-1859(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in Nu...
CVE-2014-1858__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a tempo...
CVE-2014-10069Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which ...
CVE-2014-8579TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account,...
CVE-2014-8540The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitra...
CVE-2014-8336The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attacke...
CVE-2014-8335(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for Word...
CVE-2014-7862The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at...
CVE-2014-9515CRITICAL9.8Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbi...
CVE-2014-8119The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash...
CVE-2014-4978The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary file...
CVE-2014-3630XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2...
CVE-2014-0121The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary comman...
CVE-2014-0120Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the a...
CVE-2014-3651JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a larg...
CVE-2014-4914The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows re...
CVE-2014-8389cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21....
CVE-2014-8358Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014)...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now