2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-10075 | — | — | 3.5% | Oct 5, 2018 | The karo gem 2.3.8 for Ruby allows Remote command injection via the host field. |
| CVE-2014-6050 | — | — | 4.6% | Aug 28, 2018 | phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request. |
| CVE-2014-6049 | — | — | 3.2% | Aug 28, 2018 | phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted ins... |
| CVE-2014-6048 | — | — | 5.7% | Aug 28, 2018 | phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request. |
| CVE-2014-6047 | — | — | 5.7% | Aug 28, 2018 | phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever... |
| CVE-2014-6046 | — | — | 1.9% | Aug 28, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack th... |
| CVE-2014-6045 | — | — | 2.1% | Aug 28, 2018 | SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to exec... |
| CVE-2014-4932 | — | — | 1.2% | Aug 28, 2018 | Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attac... |
| CVE-2014-10074 | — | — | 2.8% | Aug 27, 2018 | Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release... |
| CVE-2014-4150 | — | — | 0.5% | Jul 20, 2018 | The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via ... |
| CVE-2014-2296 | — | — | 2.1% | Jul 20, 2018 | XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 an... |
| CVE-2014-2302 | — | — | 4.5% | Jul 19, 2018 | The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP ... |
| CVE-2014-0243 | — | — | 0.6% | Jul 19, 2018 | Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_m... |
| CVE-2014-2079 | — | — | 0.4% | Jul 16, 2018 | X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary fi... |
| CVE-2014-5220 | — | — | 0.5% | Jun 8, 2018 | The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize devic... |
| CVE-2014-10065 | — | — | 1.0% | May 31, 2018 | Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript:... |
| CVE-2014-10064 | — | — | 1.3% | May 31, 2018 | The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string repr... |
| CVE-2014-10067 | — | — | 1.2% | May 29, 2018 | paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it shou... |
| CVE-2014-2552 | — | — | 3.8% | Apr 27, 2018 | Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, ... |
| CVE-2014-1846 | — | — | 0.4% | Apr 27, 2018 | Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method. |
| CVE-2014-1845 | — | — | 0.4% | Apr 27, 2018 | An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging fai... |
| CVE-2014-0841 | — | — | 0.2% | Apr 27, 2018 | IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it ea... |
| CVE-2014-0882 | — | — | 1.2% | Apr 25, 2018 | Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might... |
| CVE-2014-0881 | — | — | 2.1% | Apr 25, 2018 | The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows... |
| CVE-2014-0872 | — | — | 0.3% | Apr 25, 2018 | The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow loc... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now