2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8708 | — | — | 3.0% | Mar 17, 2017 | Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature. |
| CVE-2014-8707 | — | — | 0.7% | Mar 17, 2017 | Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbit... |
| CVE-2014-8706 | — | — | 1.1% | Mar 17, 2017 | Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) add... |
| CVE-2014-8705 | — | — | 1.5% | Mar 17, 2017 | PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitra... |
| CVE-2014-8704 | — | — | 2.0% | Mar 17, 2017 | Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitra... |
| CVE-2014-8703 | — | — | 0.8% | Mar 17, 2017 | Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HT... |
| CVE-2014-8702 | — | — | 1.4% | Mar 17, 2017 | Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array fo... |
| CVE-2014-8701 | — | — | 1.5% | Mar 17, 2017 | Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the un... |
| CVE-2014-9921 | — | — | 3.0% | Mar 14, 2017 | Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.... |
| CVE-2014-9920 | — | — | 1.0% | Mar 14, 2017 | Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 bef... |
| CVE-2014-8688 | HIGH | 7.5 | 1.3% | Mar 14, 2017 | An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in c... |
| CVE-2014-3926 | — | — | 1.4% | Mar 13, 2017 | Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9 allows remote attackers to inject arbitrary web scri... |
| CVE-2014-9645 | — | — | 0.6% | Mar 12, 2017 | The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restriction... |
| CVE-2014-9916 | MEDIUM | 6.1 | 0.9% | Feb 24, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web sc... |
| CVE-2014-4677 | — | — | 0.6% | Feb 22, 2017 | The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local us... |
| CVE-2014-9905 | MEDIUM | 6.1 | 1.2% | Feb 17, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to i... |
| CVE-2014-9760 | MEDIUM | 6.1 | 1.2% | Feb 13, 2017 | Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers ... |
| CVE-2014-9914 | HIGH | 7.8 | 0.3% | Feb 7, 2017 | Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows l... |
| CVE-2014-9772 | — | — | 2.6% | Jan 23, 2017 | The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter v... |
| CVE-2014-8362 | — | — | 3.3% | Jan 23, 2017 | Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other secu... |
| CVE-2014-9755 | — | — | 3.6% | Jan 20, 2017 | The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remot... |
| CVE-2014-9754 | — | — | 1.7% | Jan 20, 2017 | The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remot... |
| CVE-2014-2045 | — | — | 4.5% | Jan 20, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30... |
| CVE-2014-9913 | — | — | 1.5% | Jan 18, 2017 | Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of ... |
| CVE-2014-9910 | — | — | 0.5% | Jan 18, 2017 | An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now