2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3250The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which m...
CVE-2014-3150Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, ...
CVE-2014-2845MEDIUM5.9Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle at...
CVE-2014-0219Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial...
CVE-2014-4000Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP c...
CVE-2014-0073The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) befor...
CVE-2014-0072ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0....
CVE-2014-0115Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary fi...
CVE-2014-3624Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to ...
CVE-2014-3526HIGH7.5Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive...
CVE-2014-3600XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified...
CVE-2014-3579XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspe...
CVE-2014-2023Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo...
CVE-2014-1203CRITICAL9.8The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary comman...
CVE-2014-0691Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote atta...
CVE-2014-3744Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary fi...
CVE-2014-3741The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attack...
CVE-2014-8491The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a requ...
CVE-2014-7813Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource c...
CVE-2014-7242The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission a...
CVE-2014-3709The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote at...
CVE-2014-3706ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to ver...
CVE-2014-3531Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject a...
CVE-2014-3164cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers...
CVE-2014-9118The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary comm...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now