2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8005 | — | — | 1.2% | Nov 26, 2014 | Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows ... |
| CVE-2014-7247 | — | — | 5.3% | Nov 26, 2014 | Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ich... |
| CVE-2014-6196 | — | — | 1.4% | Nov 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere... |
| CVE-2014-6093 | — | — | 1.5% | Nov 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, ... |
| CVE-2014-9039 | — | — | 2.4% | Nov 25, 2014 | wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote ... |
| CVE-2014-9038 | — | — | 3.8% | Nov 25, 2014 | wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remo... |
| CVE-2014-9037 | — | — | 2.6% | Nov 25, 2014 | WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obt... |
| CVE-2014-9036 | — | — | 2.3% | Nov 25, 2014 | Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x befo... |
| CVE-2014-9035 | — | — | 2.3% | Nov 25, 2014 | Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3... |
| CVE-2014-9034 | — | — | 83.2% | Nov 25, 2014 | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all... |
| CVE-2014-9033 | — | — | 2.0% | Nov 25, 2014 | Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote ... |
| CVE-2014-9032 | — | — | 2.8% | Nov 25, 2014 | Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x b... |
| CVE-2014-9031 | — | — | 5.0% | Nov 25, 2014 | Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and ... |
| CVE-2014-3605 | — | — | — | Nov 25, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation du... |
| CVE-2014-8004 | — | — | 1.6% | Nov 25, 2014 | Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP se... |
| CVE-2014-8002 | — | — | 2.2% | Nov 25, 2014 | Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute ... |
| CVE-2014-8001 | — | — | 2.5% | Nov 25, 2014 | Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via ... |
| CVE-2014-8678 | — | — | 2.3% | Nov 25, 2014 | The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via... |
| CVE-2014-8558 | — | — | 1.7% | Nov 25, 2014 | JExperts Channel Platform 5.0.33_CCB allows remote authenticated users to bypass access restrictions via crafted action ... |
| CVE-2014-8420 | — | — | 24.0% | Nov 25, 2014 | The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before... |
| CVE-2014-8368 | — | — | 2.8% | Nov 25, 2014 | The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain... |
| CVE-2014-8367 | — | — | 1.7% | Nov 25, 2014 | SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x befor... |
| CVE-2014-7839 | — | — | 2.0% | Nov 25, 2014 | DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parame... |
| CVE-2014-1421 | — | — | 0.5% | Nov 25, 2014 | mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows lo... |
| CVE-2014-8349 | — | — | 1.5% | Nov 24, 2014 | Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise Edition (EE) 6.2 SP8 and earlier allows remote aut... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now