2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2014-2228CRITICAL9.8The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe dese...
CVE-2014-3622CRITICAL9.8Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might a...
CVE-2014-3879CRITICAL9.8OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a po...
CVE-2014-4967CRITICAL9.8Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by ...
CVE-2014-4966CRITICAL9.8Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data...
CVE-2014-4651CRITICAL9.8It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attack...
CVE-2014-8089CRITICAL9.8SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the ...
CVE-2014-7236CRITICAL9.1Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary ...
CVE-2014-4981CRITICAL9.8LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization...
CVE-2014-4198CRITICAL9.1A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that ...
CVE-2014-4170CRITICAL9.8A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restric...
CVE-2014-3919CRITICAL9.3A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspec...
CVE-2014-9390CRITICAL9.8Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS...
CVE-2014-2595CRITICAL9.8Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a perm...
CVE-2014-0234CRITICAL9.8The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a M...
CVE-2014-9753CRITICAL9.8confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing us...
CVE-2014-2052CRITICAL9.8Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitra...
CVE-2014-8739CRITICAL9.8Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery...
CVE-2014-5091CRITICAL9.8A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, wh...
CVE-2014-5087CRITICAL9.8A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could l...
CVE-2014-9530CRITICAL9.8A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impac...
CVE-2014-2025CRITICAL9.8Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5...
CVE-2014-8322CRITICAL9.8Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac...
CVE-2014-5039CRITICAL9.6Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attacke...
CVE-2014-3719CRITICAL9.8Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management sys...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now