2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-10075The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
CVE-2014-6050phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
CVE-2014-6049phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted ins...
CVE-2014-6048phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
CVE-2014-6047phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever...
CVE-2014-6046Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack th...
CVE-2014-6045SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to exec...
CVE-2014-4932Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attac...
CVE-2014-10074Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release...
CVE-2014-4150The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via ...
CVE-2014-2296XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 an...
CVE-2014-2302The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP ...
CVE-2014-0243Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_m...
CVE-2014-2079X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary fi...
CVE-2014-5220The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize devic...
CVE-2014-10065Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript:...
CVE-2014-10064The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string repr...
CVE-2014-10067paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it shou...
CVE-2014-2552Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, ...
CVE-2014-1846Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.
CVE-2014-1845An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging fai...
CVE-2014-0841IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it ea...
CVE-2014-0882Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might...
CVE-2014-0881The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows...
CVE-2014-0872The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow loc...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now