2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-8708——Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
CVE-2014-8707——Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbit...
CVE-2014-8706——Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) add...
CVE-2014-8705——PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitra...
CVE-2014-8704——Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitra...
CVE-2014-8703——Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HT...
CVE-2014-8702——Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array fo...
CVE-2014-8701——Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the un...
CVE-2014-9921——Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1....
CVE-2014-9920——Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 bef...
CVE-2014-8688HIGH7.5An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in c...
CVE-2014-3926——Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9 allows remote attackers to inject arbitrary web scri...
CVE-2014-9645——The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restriction...
CVE-2014-9916MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web sc...
CVE-2014-4677——The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local us...
CVE-2014-9905MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to i...
CVE-2014-9760MEDIUM6.1Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers ...
CVE-2014-9914HIGH7.8Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows l...
CVE-2014-9772——The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter v...
CVE-2014-8362——Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other secu...
CVE-2014-9755——The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remot...
CVE-2014-9754——The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remot...
CVE-2014-2045——Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30...
CVE-2014-9913——Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of ...
CVE-2014-9910——An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now