2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8357 | — | — | 5.4% | Oct 17, 2017 | backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a ... |
| CVE-2014-2664 | — | — | 2.9% | Oct 17, 2017 | Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/Profi... |
| CVE-2014-2277 | HIGH | 7.1 | 0.4% | Oct 17, 2017 | The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive informati... |
| CVE-2014-9733 | — | — | 1.4% | Oct 17, 2017 | nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified ... |
| CVE-2014-9697 | — | — | 0.8% | Oct 17, 2017 | Huawei USG9560/9520/9580 before V300R001C01SPC300 allows remote attackers to cause a memory leak or denial of service (m... |
| CVE-2014-9678 | — | — | 1.0% | Oct 17, 2017 | FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile... |
| CVE-2014-9677 | — | — | 1.2% | Oct 17, 2017 | Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inj... |
| CVE-2014-9489 | — | — | 2.3% | Oct 17, 2017 | The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib befor... |
| CVE-2014-9487 | — | — | 2.0% | Oct 17, 2017 | The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary fil... |
| CVE-2014-8324 | — | — | 4.2% | Oct 17, 2017 | network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via... |
| CVE-2014-8323 | — | — | 3.3% | Oct 17, 2017 | buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) vi... |
| CVE-2014-0208 | — | — | 0.8% | Oct 16, 2017 | Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remo... |
| CVE-2014-9148 | — | — | 11.4% | Oct 16, 2017 | Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update"... |
| CVE-2014-9147 | — | — | 11.4% | Oct 16, 2017 | Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup fil... |
| CVE-2014-8621 | — | — | 3.0% | Oct 16, 2017 | SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execut... |
| CVE-2014-8087 | — | — | 1.9% | Oct 16, 2017 | Cross-site scripting (XSS) vulnerability in the post highlights plugin before 2.6.1 for WordPress allows remote attacker... |
| CVE-2014-7851 | — | — | 1.0% | Oct 16, 2017 | oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote au... |
| CVE-2014-3702 | — | — | 1.9% | Oct 16, 2017 | Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files ... |
| CVE-2014-0029 | — | — | 0.8% | Oct 16, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote a... |
| CVE-2014-9092 | — | — | 3.2% | Oct 10, 2017 | libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related... |
| CVE-2014-9474 | — | — | 4.3% | Oct 10, 2017 | Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have uns... |
| CVE-2014-0030 | — | — | 16.9% | Oct 10, 2017 | The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks... |
| CVE-2014-8957 | — | — | 1.2% | Oct 6, 2017 | Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary w... |
| CVE-2014-2903 | — | — | 1.0% | Oct 6, 2017 | CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a... |
| CVE-2014-0047 | — | — | 0.4% | Oct 6, 2017 | Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage. |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now