2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7174 | MEDIUM | 5.3 | 1.3% | Jun 1, 2020 | FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature. |
| CVE-2014-7173 | CRITICAL | 9.8 | 2.5% | Jun 1, 2020 | FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx2... |
| CVE-2014-1423 | MEDIUM | 5.5 | 0.8% | May 7, 2020 | signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from quer... |
| CVE-2014-2723 | HIGH | 8.8 | 1.7% | Mar 19, 2020 | In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may ... |
| CVE-2014-2722 | HIGH | 8.8 | 1.7% | Mar 19, 2020 | In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may ... |
| CVE-2014-2721 | HIGH | 8.8 | 2.3% | Mar 19, 2020 | In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may ... |
| CVE-2014-1634 | CRITICAL | 9.8 | 1.4% | Mar 9, 2020 | SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subsc... |
| CVE-2014-7914 | HIGH | 8.1 | 0.5% | Feb 21, 2020 | btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which al... |
| CVE-2014-3557 | — | — | — | Feb 20, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2014-4019 | HIGH | 7.5 | 12.4% | Feb 20, 2020 | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient... |
| CVE-2014-4650 | CRITICAL | 9.8 | 24.1% | Feb 20, 2020 | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path ... |
| CVE-2014-7951 | MEDIUM | 4.6 | 1.1% | Feb 20, 2020 | Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate att... |
| CVE-2014-4659 | MEDIUM | 5.5 | 0.4% | Feb 20, 2020 | Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credentia... |
| CVE-2014-4658 | MEDIUM | 5.5 | 0.4% | Feb 20, 2020 | The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, whic... |
| CVE-2014-4657 | CRITICAL | 9.8 | 4.3% | Feb 20, 2020 | The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers... |
| CVE-2014-3484 | CRITICAL | 9.8 | 2.1% | Feb 20, 2020 | Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 ... |
| CVE-2014-4678 | CRITICAL | 9.8 | 5.1% | Feb 20, 2020 | The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers... |
| CVE-2014-4660 | MEDIUM | 5.5 | 0.4% | Feb 20, 2020 | Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list,... |
| CVE-2014-9617 | MEDIUM | 6.1 | 8.0% | Feb 19, 2020 | Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to re... |
| CVE-2014-9615 | MEDIUM | 6.1 | 3.7% | Feb 19, 2020 | Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or H... |
| CVE-2014-9614 | CRITICAL | 9.8 | 66.6% | Feb 19, 2020 | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it eas... |
| CVE-2014-9613 | CRITICAL | 9.8 | 4.1% | Feb 19, 2020 | Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co... |
| CVE-2014-9612 | CRITICAL | 9.8 | 4.9% | Feb 19, 2020 | SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1... |
| CVE-2014-9609 | MEDIUM | 5.3 | 10.6% | Feb 19, 2020 | Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0... |
| CVE-2014-9608 | MEDIUM | 6.1 | 3.9% | Feb 19, 2020 | Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x bef... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now