2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-0674Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which...
CVE-2014-1242Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof ...
CVE-2014-0494Adobe Digital Editions 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption ...
CVE-2014-0675The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate ...
CVE-2014-0979The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle...
CVE-2014-0006The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows ...
CVE-2014-0807data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and earlier, and 2.11.0 through 2.12.2, all...
CVE-2014-0806The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for ...
CVE-2014-0677The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service ...
CVE-2014-0676Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bu...
CVE-2014-0662The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a deni...
CVE-2014-0661The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42...
CVE-2014-0660Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-c...
CVE-2014-1637Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which a...
CVE-2014-1636Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe...
CVE-2014-0672The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows rem...
CVE-2014-0671Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and con...
CVE-2014-0670Cross-site scripting (XSS) vulnerability in the Search and Play interface in Cisco MediaSense allows remote attackers to...
CVE-2014-0669The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series d...
CVE-2014-1620Multiple cross-site scripting (XSS) vulnerabilities in add.php in HIOX Guest Book (HGB) 5.0 allow remote attackers to in...
CVE-2014-1619Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQ...
CVE-2014-1618Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com...
CVE-2014-1452Stack-based buffer overflow in lib/snmpagent.c in bsnmpd, as used in FreeBSD 8.3 through 10.0, allows remote attackers t...
CVE-2014-0753Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a d...
CVE-2014-0010Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x bef...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now