2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9292Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress al...
CVE-2014-8877The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plug...
CVE-2014-7259SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, w...
CVE-2014-7258Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91 and earlier, when running certain versions of Inter...
CVE-2014-7256The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SE...
CVE-2014-7254Unspecified vulnerability in ARROWS Me F-11D allows physically proximate attackers to read or modify flash memory via un...
CVE-2014-7253FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute ...
CVE-2014-7252Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT D...
CVE-2014-7243LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, ...
CVE-2014-9140Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a ...
CVE-2014-8990default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacha...
CVE-2014-8123Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of servi...
CVE-2014-6040GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds rea...
CVE-2014-4703lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the c...
CVE-2014-4702The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configu...
CVE-2014-4701The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configu...
CVE-2014-3627The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentica...
CVE-2014-3561The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the co...
CVE-2014-2273The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary me...
CVE-2014-9215SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 ...
CVE-2014-9212Multiple cross-site scripting (XSS) vulnerabilities in Altitude uAgent in Altitude uCI (Unified Customer Interaction) 7....
CVE-2014-9144Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metac...
CVE-2014-9143Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect us...
CVE-2014-9142Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers t...
CVE-2014-9129Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPr...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now