2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9342Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in...
CVE-2014-9219Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allow...
CVE-2014-9218libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows re...
CVE-2014-9217Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.
CVE-2014-8600Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, an...
CVE-2014-8371VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not prope...
CVE-2014-4880Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta...
CVE-2014-4631RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or u...
CVE-2014-3797Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote att...
CVE-2014-3616nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, ...
CVE-2014-1693Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inje...
CVE-2014-9304Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and e...
CVE-2014-9303EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator ...
CVE-2014-9302Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Servi...
CVE-2014-9301Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows ...
CVE-2014-9300Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Servic...
CVE-2014-8868EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain ...
CVE-2014-9117MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attacke...
CVE-2014-8651The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to...
CVE-2014-9278The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows ...
CVE-2014-7251XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP...
CVE-2014-6140IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across diffe...
CVE-2014-5429DNP Master Driver 3.02 and earlier in Elipse SCADA 2.29 build 141 and earlier, E3 1.0 through 4.6, and Elipse Power 1.0 ...
CVE-2014-4629EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read ...
CVE-2014-3099Unspecified vulnerability in the Security component in IBM Systems Director 6.3.0 through 6.3.5 allows local users to ob...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now