2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9292 | — | — | 1.9% | Dec 5, 2014 | Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress al... |
| CVE-2014-8877 | — | — | 14.8% | Dec 5, 2014 | The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plug... |
| CVE-2014-7259 | — | — | 1.0% | Dec 5, 2014 | SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, w... |
| CVE-2014-7258 | — | — | 1.2% | Dec 5, 2014 | Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91 and earlier, when running certain versions of Inter... |
| CVE-2014-7256 | — | — | 1.8% | Dec 5, 2014 | The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SE... |
| CVE-2014-7254 | — | — | 0.3% | Dec 5, 2014 | Unspecified vulnerability in ARROWS Me F-11D allows physically proximate attackers to read or modify flash memory via un... |
| CVE-2014-7253 | — | — | 0.4% | Dec 5, 2014 | FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute ... |
| CVE-2014-7252 | — | — | 0.4% | Dec 5, 2014 | Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT D... |
| CVE-2014-7243 | — | — | 1.4% | Dec 5, 2014 | LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, ... |
| CVE-2014-9140 | — | — | 5.8% | Dec 5, 2014 | Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a ... |
| CVE-2014-8990 | — | — | 5.2% | Dec 5, 2014 | default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacha... |
| CVE-2014-8123 | — | — | 3.6% | Dec 5, 2014 | Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of servi... |
| CVE-2014-6040 | — | — | 6.6% | Dec 5, 2014 | GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds rea... |
| CVE-2014-4703 | — | — | 1.1% | Dec 5, 2014 | lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the c... |
| CVE-2014-4702 | — | — | 0.4% | Dec 5, 2014 | The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configu... |
| CVE-2014-4701 | — | — | 0.5% | Dec 5, 2014 | The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configu... |
| CVE-2014-3627 | — | — | 3.0% | Dec 5, 2014 | The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentica... |
| CVE-2014-3561 | — | — | 0.4% | Dec 5, 2014 | The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the co... |
| CVE-2014-2273 | — | — | 0.3% | Dec 5, 2014 | The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary me... |
| CVE-2014-9215 | — | — | 2.3% | Dec 5, 2014 | SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 ... |
| CVE-2014-9212 | — | — | 1.1% | Dec 5, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Altitude uAgent in Altitude uCI (Unified Customer Interaction) 7.... |
| CVE-2014-9144 | — | — | 8.6% | Dec 5, 2014 | Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metac... |
| CVE-2014-9143 | — | — | 4.0% | Dec 5, 2014 | Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect us... |
| CVE-2014-9142 | — | — | 3.2% | Dec 5, 2014 | Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers t... |
| CVE-2014-9129 | — | — | 1.5% | Dec 5, 2014 | Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPr... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now