2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-9292——Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress al...
CVE-2014-8877——The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plug...
CVE-2014-7259——SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, w...
CVE-2014-7258——Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91 and earlier, when running certain versions of Inter...
CVE-2014-7256——The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SE...
CVE-2014-7254——Unspecified vulnerability in ARROWS Me F-11D allows physically proximate attackers to read or modify flash memory via un...
CVE-2014-7253——FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute ...
CVE-2014-7252——Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT D...
CVE-2014-7243——LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, ...
CVE-2014-9140——Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a ...
CVE-2014-8990——default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacha...
CVE-2014-8123——Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of servi...
CVE-2014-6040——GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds rea...
CVE-2014-4703——lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the c...
CVE-2014-4702——The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configu...
CVE-2014-4701——The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configu...
CVE-2014-3627——The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentica...
CVE-2014-3561——The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the co...
CVE-2014-2273——The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary me...
CVE-2014-9215——SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 ...
CVE-2014-9212——Multiple cross-site scripting (XSS) vulnerabilities in Altitude uAgent in Altitude uCI (Unified Customer Interaction) 7....
CVE-2014-9144——Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metac...
CVE-2014-9143——Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect us...
CVE-2014-9142——Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers t...
CVE-2014-9129——Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPr...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now