AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-4650

CRITICAL · CVSS 9.8 EPSS 24.70%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-02-20 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 24.7% probability of exploitation in the next 30 days. It may be remotely exploitable.

CVE
CVE-2014-4650
Severity
CRITICAL
CVSS
9.8
EPSS
24.70%

Original NVD Description

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

Related CVEs

Other vulnerabilities affecting the same vendor(s)