2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-3250——The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which m...
CVE-2014-3150——Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, ...
CVE-2014-2845MEDIUM5.9Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle at...
CVE-2014-0219——Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial...
CVE-2014-4000——Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP c...
CVE-2014-0073——The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) befor...
CVE-2014-0072——ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0....
CVE-2014-0115——Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary fi...
CVE-2014-3624——Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to ...
CVE-2014-3526HIGH7.5Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive...
CVE-2014-3600——XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified...
CVE-2014-3579——XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspe...
CVE-2014-2023——Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo...
CVE-2014-1203CRITICAL9.8The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary comman...
CVE-2014-0691——Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote atta...
CVE-2014-3744——Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary fi...
CVE-2014-3741——The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attack...
CVE-2014-8491——The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a requ...
CVE-2014-7813——Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource c...
CVE-2014-7242——The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission a...
CVE-2014-3709——The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote at...
CVE-2014-3706——ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to ver...
CVE-2014-3531——Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject a...
CVE-2014-3164——cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers...
CVE-2014-9118——The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary comm...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now