2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-0802Directory traversal vulnerability in the aokitaka ZIP with Pass application 4.5.7 and earlier, and ZIP with Pass Pro app...
CVE-2014-0659The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x...
CVE-2014-0618Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X...
CVE-2014-0978Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to h...
CVE-2014-0977Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5...
CVE-2014-1408The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which...
CVE-2014-1407Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow...
CVE-2014-1406CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 a...
CVE-2014-1405Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attac...
CVE-2014-0664The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) vi...
CVE-2014-0663Cross-site scripting (XSS) vulnerability in the web framework in Cisco Secure Access Control System (ACS) allows remote ...
CVE-2014-0658Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP head...
CVE-2014-1236Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to ha...
CVE-2014-1234The paratrooper-newrelic gem 1.0.1 for Ruby allows local users to obtain the X-Api-Key value by listing the curl process...
CVE-2014-1233The paratrooper-pingdom gem 1.0.0 for Ruby allows local users to obtain the App-Key, username, and password values by li...
CVE-2014-0752The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via ...
CVE-2014-0657The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly hand...
CVE-2014-0656Cisco Context Directory Agent (CDA) allows remote authenticated users to trigger the omission of certain user-interface ...
CVE-2014-0655The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers t...
CVE-2014-0654Cisco Context Directory Agent (CDA) allows remote attackers to modify the cache via a replay attack involving crafted RA...
CVE-2014-0653The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers t...
CVE-2014-0652Cross-site scripting (XSS) vulnerability in the Mappings page in Cisco Context Directory Agent (CDA) allows remote attac...
CVE-2014-0651The administrative interface in Cisco Context Directory Agent (CDA) does not properly enforce authorization requirements...
CVE-2014-1232Cross-site scripting (XSS) vulnerability in the Foliopress WYSIWYG plugin before 2.6.8.5 for WordPress allows remote att...
CVE-2014-0621Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow rem...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now