2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-5028——The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote aut...
CVE-2014-5132——Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.
CVE-2014-5131——Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leverag...
CVE-2014-5130——Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via ve...
CVE-2014-4959——**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to ex...
CVE-2014-0486——Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message...
CVE-2014-2293——Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and d...
CVE-2014-2048——The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure ...
CVE-2014-4912——An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
CVE-2014-4928——SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execut...
CVE-2014-3990——The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to condu...
CVE-2014-2032——Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote atta...
CVE-2014-2031——Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote atta...
CVE-2014-1665——Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary ...
CVE-2014-1457——Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attacke...
CVE-2014-1215——Multiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors relat...
CVE-2014-5450——Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to o...
CVE-2014-5443——Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vector...
CVE-2014-2885——Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving...
CVE-2014-2884——The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restricti...
CVE-2014-2675——Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress all...
CVE-2014-2674——Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attacker...
CVE-2014-2652——SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attack...
CVE-2014-2550——Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote ...
CVE-2014-2297——Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for Wor...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now