2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-10075——The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
CVE-2014-6050——phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
CVE-2014-6049——phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted ins...
CVE-2014-6048——phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
CVE-2014-6047——phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever...
CVE-2014-6046——Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack th...
CVE-2014-6045——SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to exec...
CVE-2014-4932——Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attac...
CVE-2014-10074——Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release...
CVE-2014-4150——The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via ...
CVE-2014-2296——XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 an...
CVE-2014-2302——The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP ...
CVE-2014-0243——Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_m...
CVE-2014-2079——X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary fi...
CVE-2014-5220——The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize devic...
CVE-2014-10065——Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript:...
CVE-2014-10064——The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string repr...
CVE-2014-10067——paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it shou...
CVE-2014-2552——Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, ...
CVE-2014-1846——Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.
CVE-2014-1845——An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging fai...
CVE-2014-0841——IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it ea...
CVE-2014-0882——Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might...
CVE-2014-0881——The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows...
CVE-2014-0872——The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow loc...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now