2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-9635Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41...
CVE-2014-9634Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it ...
CVE-2014-9624CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
CVE-2014-9565Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switc...
CVE-2014-6438The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service ...
CVE-2014-8677The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and...
CVE-2014-8676Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke...
CVE-2014-8675Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all...
CVE-2014-9497Buffer overflow in mpg123 before 1.18.0.
CVE-2014-8872Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after...
CVE-2014-8393DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel...
CVE-2014-8163Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
CVE-2014-9558Multiple SQL injection vulnerabilities in SmartCMS v.2.
CVE-2014-9557MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2.
CVE-2014-9514Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.
CVE-2014-9513Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
CVE-2014-9483Emacs 24.4 allows remote attackers to bypass security restrictions.
CVE-2014-9469Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
CVE-2014-9312Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
CVE-2014-8900Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6...
CVE-2014-8871Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 an...
CVE-2014-8753Multiple cross-site scripting (XSS) vulnerabilities in Cit-e-Net Cit-e-Access 6.
CVE-2014-8428Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
CVE-2014-8426Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.
CVE-2014-8168Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now