2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-8708Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
CVE-2014-8707Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbit...
CVE-2014-8706Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) add...
CVE-2014-8705PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitra...
CVE-2014-8704Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitra...
CVE-2014-8703Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HT...
CVE-2014-8702Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array fo...
CVE-2014-8701Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the un...
CVE-2014-9921Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1....
CVE-2014-9920Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 bef...
CVE-2014-8688HIGH7.5An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in c...
CVE-2014-3926Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9 allows remote attackers to inject arbitrary web scri...
CVE-2014-9645The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restriction...
CVE-2014-9916MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web sc...
CVE-2014-4677The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local us...
CVE-2014-9905MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to i...
CVE-2014-9760MEDIUM6.1Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers ...
CVE-2014-9914HIGH7.8Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows l...
CVE-2014-9772The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter v...
CVE-2014-8362Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other secu...
CVE-2014-9755The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remot...
CVE-2014-9754The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remot...
CVE-2014-2045Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30...
CVE-2014-9913Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of ...
CVE-2014-9910An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now