2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-6120——IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2,...
CVE-2014-6633——The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7,...
CVE-2014-3999——The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge o...
CVE-2014-3114——The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to e...
CVE-2014-2078——The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive informatio...
CVE-2014-1946——OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypa...
CVE-2014-1889——The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain...
CVE-2014-1400——The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users ...
CVE-2014-1399——The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate...
CVE-2014-1398——The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate...
CVE-2014-0158——Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause ...
CVE-2014-1226——The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permission...
CVE-2014-5072——Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote...
CVE-2014-5034——Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remo...
CVE-2014-2359——OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or s...
CVE-2014-3413——The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, w...
CVE-2014-9959——An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9958——An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9957——An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9956——An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9955——An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9954——An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-9953——An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel...
CVE-2014-6604——Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress ...
CVE-2014-5170——The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveragin...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now