2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-6120IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2,...
CVE-2014-6633The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7,...
CVE-2014-3999The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge o...
CVE-2014-3114The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to e...
CVE-2014-2078The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive informatio...
CVE-2014-1946OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypa...
CVE-2014-1889The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain...
CVE-2014-1400The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users ...
CVE-2014-1399The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate...
CVE-2014-1398The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate...
CVE-2014-0158Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause ...
CVE-2014-1226The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permission...
CVE-2014-5072Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote...
CVE-2014-5034Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remo...
CVE-2014-2359OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or s...
CVE-2014-3413The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, w...
CVE-2014-9959An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9958An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9957An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9956An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9955An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9954An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9953An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-6604Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress ...
CVE-2014-5170The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveragin...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now