2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3250 | — | — | 0.9% | Dec 11, 2017 | The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which m... |
| CVE-2014-3150 | — | — | 1.9% | Nov 15, 2017 | Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, ... |
| CVE-2014-2845 | MEDIUM | 5.9 | 0.9% | Nov 15, 2017 | Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle at... |
| CVE-2014-0219 | — | — | 0.7% | Nov 15, 2017 | Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial... |
| CVE-2014-4000 | — | — | 1.7% | Nov 15, 2017 | Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP c... |
| CVE-2014-0073 | — | — | 8.1% | Oct 30, 2017 | The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) befor... |
| CVE-2014-0072 | — | — | 7.7% | Oct 30, 2017 | ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.... |
| CVE-2014-0115 | — | — | 5.3% | Oct 30, 2017 | Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary fi... |
| CVE-2014-3624 | — | — | 3.8% | Oct 30, 2017 | Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to ... |
| CVE-2014-3526 | HIGH | 7.5 | 2.3% | Oct 30, 2017 | Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive... |
| CVE-2014-3600 | — | — | 9.9% | Oct 27, 2017 | XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified... |
| CVE-2014-3579 | — | — | 4.6% | Oct 27, 2017 | XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspe... |
| CVE-2014-2023 | — | — | 4.1% | Oct 26, 2017 | Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo... |
| CVE-2014-1203 | CRITICAL | 9.8 | 15.6% | Oct 24, 2017 | The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary comman... |
| CVE-2014-0691 | — | — | 1.0% | Oct 24, 2017 | Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote atta... |
| CVE-2014-3744 | — | — | 34.0% | Oct 23, 2017 | Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary fi... |
| CVE-2014-3741 | — | — | 3.8% | Oct 23, 2017 | The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attack... |
| CVE-2014-8491 | — | — | 1.9% | Oct 18, 2017 | The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a requ... |
| CVE-2014-7813 | — | — | 1.0% | Oct 18, 2017 | Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource c... |
| CVE-2014-7242 | — | — | 0.6% | Oct 18, 2017 | The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission a... |
| CVE-2014-3709 | — | — | 0.8% | Oct 18, 2017 | The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote at... |
| CVE-2014-3706 | — | — | 0.7% | Oct 18, 2017 | ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to ver... |
| CVE-2014-3531 | — | — | 1.2% | Oct 18, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject a... |
| CVE-2014-3164 | — | — | 1.0% | Oct 18, 2017 | cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers... |
| CVE-2014-9118 | — | — | 53.4% | Oct 17, 2017 | The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary comm... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now