2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9579 | — | — | 1.7% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtai... |
| CVE-2014-9578 | — | — | 2.2% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allo... |
| CVE-2014-9577 | — | — | 1.8% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated... |
| CVE-2014-9576 | — | — | 2.3% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !... |
| CVE-2014-9575 | — | — | 2.4% | Jan 8, 2015 | VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read... |
| CVE-2014-9473 | — | — | 14.6% | Jan 8, 2015 | Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows r... |
| CVE-2014-9569 | — | — | 1.8% | Jan 7, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver Business Client (NWBC) for HTML 3.0 allow remote at... |
| CVE-2014-9493 | — | — | 2.8% | Jan 7, 2015 | The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenti... |
| CVE-2014-9221 | — | — | 3.8% | Jan 7, 2015 | strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer derefe... |
| CVE-2014-1425 | — | — | 0.4% | Jan 7, 2015 | cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup... |
| CVE-2014-9567 | — | — | 43.3% | Jan 7, 2015 | Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem... |
| CVE-2014-8993 | — | — | 1.9% | Jan 7, 2015 | Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev40, 7.6.0 before 7... |
| CVE-2014-3779 | — | — | 3.5% | Jan 7, 2015 | Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ADSelfService Plus before 5.2 Build 5202 allows remote att... |
| CVE-2014-9486 | — | — | — | Jan 7, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9447. Reason: This candidate is a duplicate of... |
| CVE-2014-4642 | — | — | — | Jan 7, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2014-4641 | — | — | — | Jan 7, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2014-4640 | — | — | — | Jan 7, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2014-0631 | — | — | — | Jan 7, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2014-4639 | — | — | 2.2% | Jan 7, 2015 | EMC Documentum Web Development Kit (WDK) before 6.8 does not properly generate random numbers for a certain parameter re... |
| CVE-2014-4638 | — | — | 2.3% | Jan 7, 2015 | EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to conduct frame-injection attacks and obtai... |
| CVE-2014-4637 | — | — | 2.3% | Jan 7, 2015 | Open redirect vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to redirect u... |
| CVE-2014-4636 | — | — | 1.1% | Jan 7, 2015 | Cross-site request forgery (CSRF) vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote att... |
| CVE-2014-4635 | — | — | 1.9% | Jan 7, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum Web Development Kit (WDK) before 6.8 allow remote ... |
| CVE-2014-9528 | — | — | 2.3% | Jan 6, 2015 | SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListControlle... |
| CVE-2014-9527 | — | — | 7.9% | Jan 6, 2015 | HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now