2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4829 | — | — | 0.6% | Nov 28, 2014 | Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch... |
| CVE-2014-3407 | — | — | 1.7% | Nov 28, 2014 | The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly all... |
| CVE-2014-5426 | — | — | 1.3% | Nov 27, 2014 | MatrikonOPC OPC Server for DNP3 1.2.3 and earlier allows remote attackers to cause a denial of service (unhandled except... |
| CVE-2014-9104 | — | — | 0.9% | Nov 26, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Se... |
| CVE-2014-9103 | — | — | 1.9% | Nov 26, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attack... |
| CVE-2014-9102 | — | — | 1.7% | Nov 26, 2014 | Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users... |
| CVE-2014-9101 | — | — | 2.4% | Nov 26, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (b... |
| CVE-2014-9100 | — | — | 1.6% | Nov 26, 2014 | Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to in... |
| CVE-2014-9099 | — | — | 2.7% | Nov 26, 2014 | Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attacker... |
| CVE-2014-9098 | — | — | 2.9% | Nov 26, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin ... |
| CVE-2014-9097 | — | — | 5.2% | Nov 26, 2014 | Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly... |
| CVE-2014-9096 | — | — | 2.4% | Nov 26, 2014 | Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute a... |
| CVE-2014-9095 | — | — | 2.3% | Nov 26, 2014 | Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary S... |
| CVE-2014-9094 | — | — | 7.3% | Nov 26, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Vide... |
| CVE-2014-9093 | — | — | 4.1% | Nov 26, 2014 | LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and po... |
| CVE-2014-9028 | — | — | 9.8% | Nov 26, 2014 | Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code... |
| CVE-2014-8962 | — | — | 9.9% | Nov 26, 2014 | Stack-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary cod... |
| CVE-2014-8419 | — | — | 0.5% | Nov 26, 2014 | Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe... |
| CVE-2014-7142 | — | — | 24.9% | Nov 26, 2014 | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of servic... |
| CVE-2014-7141 | — | — | 76.1% | Nov 26, 2014 | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of servic... |
| CVE-2014-6610 | — | — | 1.5% | Nov 26, 2014 | Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when usin... |
| CVE-2014-6609 | — | — | 3.6% | Nov 26, 2014 | The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a deni... |
| CVE-2014-2037 | — | — | 2.4% | Nov 26, 2014 | Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) v... |
| CVE-2014-8552 | — | — | 2.0% | Nov 26, 2014 | The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7... |
| CVE-2014-8551 | — | — | 5.3% | Nov 26, 2014 | The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now