2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-8357backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a ...
CVE-2014-2664Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/Profi...
CVE-2014-2277HIGH7.1The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive informati...
CVE-2014-9733nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified ...
CVE-2014-9697Huawei USG9560/9520/9580 before V300R001C01SPC300 allows remote attackers to cause a memory leak or denial of service (m...
CVE-2014-9678FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile...
CVE-2014-9677Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inj...
CVE-2014-9489The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib befor...
CVE-2014-9487The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary fil...
CVE-2014-8324network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via...
CVE-2014-8323buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) vi...
CVE-2014-0208Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remo...
CVE-2014-9148Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update"...
CVE-2014-9147Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup fil...
CVE-2014-8621SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execut...
CVE-2014-8087Cross-site scripting (XSS) vulnerability in the post highlights plugin before 2.6.1 for WordPress allows remote attacker...
CVE-2014-7851oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote au...
CVE-2014-3702Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files ...
CVE-2014-0029Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote a...
CVE-2014-9092libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related...
CVE-2014-9474Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have uns...
CVE-2014-0030The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks...
CVE-2014-8957Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary w...
CVE-2014-2903CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a...
CVE-2014-0047Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now