7.5
    High

    CVE-2014-2364

    Last Modified: 24 Sept 2014

    Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

    Source:Metasploit
    Published:19 Jul 2014
    7
    High

    CVE-2014-2347

    Last Modified: 3 May 2014

    Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.

    Source:Jared Bird
    Published:6 May 2014
    6.8
    Medium

    CVE-2014-2341

    Last Modified: 13 Apr 2014

    Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    Source:absane
    Published:21 Apr 2014
    6.8
    Medium

    CVE-2014-2340

    Last Modified: 4 Apr 2014

    Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.

    Source:High-Tech Bridge SA
    Published:3 Apr 2014
    6.5
    Medium

    CVE-2014-2339

    Last Modified: 29 Dec 2015

    Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter.

    Source:Claepo Wang
    Published:19 Mar 2014
    5
    Medium

    CVE-2014-2324

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.

    Published:14 Mar 2014
    9.8
    Critical

    CVE-2014-2323

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

    Published:14 Mar 2014
    10
    Critical

    CVE-2014-2321

    Last Modified: 12 Apr 2025

    web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.

    Published:11 Mar 2014
    6.8
    Medium

    CVE-2014-2317

    Last Modified: 5 Mar 2014

    SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:7 Mar 2014
    4.3
    Medium

    CVE-2014-2314

    Last Modified: 7 Apr 2014

    Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.

    Source:Metasploit
    Published:7 Mar 2014
    7.5
    High

    CVE-2014-2303

    Last Modified: 10 Jan 2016

    Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.

    Source:RedTeam Pentesting GmbH
    Published:13 Jun 2014
    9.3
    Critical

    CVE-2014-2299

    Last Modified: 28 Apr 2014

    Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.

    Source:Metasploit
    Published:7 Mar 2014
    5
    Medium

    CVE-2014-2268

    Last Modified: 10 Apr 2014

    views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.

    Source:Metasploit
    Published:16 Nov 2014
    Unknown

    CVE-2014-2239

    https://www.exploit-db.com/exploits/35605

    6
    Medium

    CVE-2014-2227

    Last Modified: 19 Jan 2016

    The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

    Source:Seth Art
    Published:25 Jul 2014
    8.8
    High

    CVE-2014-2225

    Last Modified: 28 Jul 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified impact via a request to api/add/wlanconf; change the guest (3) password, (4) authentication method, or (5) restricted subnets via a request to api/set/setting/guest_access; (6) block, (7) unblock, or (8) reconnect users by MAC address via a request to api/cmd/stamgr; change the syslog (9) server or (10) port via a request to api/set/setting/rsyslogd; (11) have unspecified impact via a request to api/set/setting/smtp; change the syslog (12) server, (13) port, or (14) authentication settings via a request to api/cmd/cfgmgr; or (15) change the Unifi Controller name via a request to api/set/setting/identity.

    Source:Seth Art
    Published:8 Feb 2020
    7.5
    High

    CVE-2014-2223

    Last Modified: 28 Aug 2014

    Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in plog-content/uploads/archive/.

    Source:b0z
    Published:11 Sept 2014
    7.5
    High

    CVE-2014-2211

    Last Modified: 26 Dec 2015

    SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the rssurl parameter.

    Source:Anthony BAUBE
    Published:3 Mar 2014
    10
    Critical

    CVE-2014-2206

    Last Modified: 9 Mar 2014

    Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header.

    Source:Julien Ahrens
    Published:5 Mar 2014
    3.5
    Low

    CVE-2014-2091

    Last Modified: 26 Dec 2015

    Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the title parameter in an add_forum action. NOTE: the original disclosure also reported issues that may not cross privilege boundaries.

    Source:HauntIT
    Published:2 Mar 2014
    3.5
    Low

    CVE-2014-2090

    Last Modified: 22 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title parameter.

    Source:HauntIT
    Published:2 Mar 2014
    6.8
    Medium

    CVE-2014-2089

    Last Modified: 22 Feb 2014

    ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client_id pathname.

    Source:HauntIT
    Published:2 Mar 2014
    6.5
    Medium

    CVE-2014-2088

    Last Modified: 22 Feb 2014

    Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFiles command, and then accessing the .php file via a direct request to a certain client_id pathname.

    Source:HauntIT
    Published:2 Mar 2014
    9.3
    Critical

    CVE-2014-2087

    Last Modified: 10 Oct 2016

    Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.

    Source:Julien Ahrens
    Published:18 Mar 2014
    Low

    CVE-2014-2085

    Last Modified: 12 May 2014

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2084. Reason: This issue was MERGED into CVE-2014-2084 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2014-2084 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Luigi Vezzoso
    Published:17 May 2014
    8.5
    High

    CVE-2014-2084

    Last Modified: 12 May 2014

    Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin interface, which allows remote attackers to obtain sensitive information via a request to (1) scripts/commands/getSystemInformation or (2) scripts/commands/getNetworkConfigurationInfo, cause a denial of service (reboot) via a request to scripts/commands/reboot, or cause a denial of service (shutdown) via a request to scripts/commands/shutdown.

    Source:Luigi Vezzoso
    Published:17 May 2014
    7.5
    High

    CVE-2014-2081

    Last Modified: 26 Aug 2014

    Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 2014.x before 2014.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

    Source:José Tozo
    Published:20 Oct 2014
    9.8
    Critical

    CVE-2014-2072

    Last Modified: 26 Dec 2015

    Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks

    Source:Mohamed Shetta
    Published:8 Jan 2020
    7.5
    High

    CVE-2014-2069

    Last Modified: 26 Dec 2015

    Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx.

    Source:peng.deng
    Published:13 Apr 2018
    5
    Medium

    CVE-2014-2064

    Last Modified: 12 Apr 2025

    The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.

    Published:7 Feb 2014
    9.7
    Critical

    CVE-2014-2046

    Last Modified: 10 Oct 2016

    cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors.

    Source:Portcullis
    Published:14 May 2014
    6.1
    Medium

    CVE-2014-2045

    Last Modified: 3 Feb 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to inject arbitrary web script or HTML via the username when (1) logging in or (2) creating an account in the old interface, (3) username when creating an account in the new interface, (4) hostname in the old interface, (5) inspect parameter in the config module, (6) commands parameter in the atcommands tool, or (7) host parameter in the ping tool.

    Source:Portcullis
    Published:20 Jan 2017
    7.5
    High

    CVE-2014-2044

    Last Modified: 10 Oct 2016

    Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

    Source:Portcullis
    Published:6 Oct 2014
    6.5
    Medium

    CVE-2014-2043

    Last Modified: 10 Oct 2016

    SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands via the value parameter.

    Source:Portcullis
    Published:13 Mar 2014
    8.8
    High

    CVE-2014-2030

    Last Modified: 16 Feb 2014

    Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.

    Source:Mike Czumak
    Published:14 Nov 2013
    9.8
    Critical

    CVE-2014-2023

    Last Modified: 11 Jan 2018

    Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in mobiquo/functions/.

    Source:tintinweb
    Published:26 Oct 2017
    7.1
    High

    CVE-2014-2022

    Last Modified: 11 Jan 2018

    SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.

    Source:tintinweb
    Published:15 Oct 2014
    3.5
    Low

    CVE-2014-2021

    Last Modified: 11 Jan 2018

    Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

    Source:tintinweb
    Published:25 Oct 2014
    6.1
    Medium

    CVE-2014-2017

    Last Modified: 20 Mar 2014

    CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Source://sToRm
    Published:18 Jan 2018
    4.3
    Medium

    CVE-2014-2016

    Last Modified: 20 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise Edition 4.6.8 and earlier, 5.0.x before 5.0.11 and 5.1.x before 5.1.4 allow remote attackers to inject arbitrary web script or HTML via the searchtag parameter to the getTag function in (1) application/controllers/details.php or (2) application/controllers/tag.php.

    Source://sToRm
    Published:25 Mar 2014
    7.5
    High

    CVE-2014-2013

    Last Modified: 21 Jan 2014

    Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.

    Source:Jean-Jamil Khalife
    Published:3 Mar 2014
    5
    Medium

    CVE-2014-2009

    Last Modified: 4 Mar 2019

    The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.

    Source:Wireghoul
    Published:12 Sept 2014
    7.5
    High

    CVE-2014-2008

    Last Modified: 4 Mar 2019

    SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.

    Source:Wireghoul
    Published:12 Sept 2014
    6.8
    Medium

    CVE-2014-1990

    Last Modified: 13 Nov 2013

    Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords.

    Source:Hubert Gradek
    Published:19 Apr 2014
    10
    Critical

    CVE-2014-1982

    Last Modified: 26 Mar 2014

    The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to cli.html.

    Source:Groundworks Technologies
    Published:28 Mar 2014
    7.8
    High

    CVE-2014-1947

    Last Modified: 16 Feb 2014

    Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.

    Source:Mike Czumak
    Published:14 Nov 2013
    7.5
    High

    CVE-2014-1945

    Last Modified: 5 Mar 2014

    SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter.

    Source:High-Tech Bridge SA
    Published:7 Mar 2014
    4.3
    Medium

    CVE-2014-1944

    Last Modified: 5 Mar 2014

    Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry.

    Source:High-Tech Bridge SA
    Published:7 Mar 2014
    6.8
    Medium

    CVE-2014-1915

    Last Modified: 12 Dec 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the authentication of (1) administrators for requests that change the administrator password via an update action to sw/admin_change_password.php or (2) unspecified victims for requests that add a topic or blog entry to sw/add_topic.php. NOTE: vector 2 can be leveraged to bypass the authentication requirements for exploiting vector 1 in CVE-2014-1914.

    Source:AtT4CKxT3rR0r1ST
    Published:7 Feb 2014
    7.5
    High

    CVE-2014-1912

    Last Modified: 25 Feb 2014

    Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

    Source:Sha0
    Published:14 Jan 2014