2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8588 | — | — | 1.3% | Nov 4, 2014 | SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL... |
| CVE-2014-8587 | — | — | 1.3% | Nov 4, 2014 | SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SA... |
| CVE-2014-8586 | — | — | 40.1% | Nov 4, 2014 | SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe... |
| CVE-2014-8585 | — | — | 2.9% | Nov 4, 2014 | Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read... |
| CVE-2014-8584 | — | — | 1.6% | Nov 4, 2014 | Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin befor... |
| CVE-2014-8339 | — | — | 2.1% | Nov 4, 2014 | SQL injection vulnerability in midroll.php in Nuevolab Nuevoplayer for ClipShare 8.0 and earlier allows remote attackers... |
| CVE-2014-7176 | — | — | 2.2% | Nov 4, 2014 | SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL... |
| CVE-2014-5387 | — | — | 1.6% | Nov 4, 2014 | Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to exe... |
| CVE-2014-4311 | — | — | 5.8% | Nov 4, 2014 | Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mai... |
| CVE-2014-0204 | — | — | 1.4% | Nov 3, 2014 | OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the s... |
| CVE-2014-7228 | — | — | 55.1% | Nov 3, 2014 | Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb... |
| CVE-2014-0490 | — | — | 3.6% | Nov 3, 2014 | The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote... |
| CVE-2014-0489 | — | — | 3.6% | Nov 3, 2014 | APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote atta... |
| CVE-2014-0488 | — | — | 2.1% | Nov 3, 2014 | APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which... |
| CVE-2014-0487 | — | — | 1.9% | Nov 3, 2014 | APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since he... |
| CVE-2014-8494 | — | — | 0.5% | Nov 3, 2014 | ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe,... |
| CVE-2014-8350 | — | — | 3.1% | Nov 3, 2014 | Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as de... |
| CVE-2014-8080 | — | — | 5.5% | Nov 3, 2014 | The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attacker... |
| CVE-2014-5507 | — | — | 0.9% | Nov 3, 2014 | iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local user... |
| CVE-2014-5272 | — | — | 2.6% | Nov 3, 2014 | libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote a... |
| CVE-2014-5271 | — | — | 4.8% | Nov 3, 2014 | Heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFMpeg before 1.1.14, 1.2.x ... |
| CVE-2014-3712 | — | — | 1.7% | Nov 3, 2014 | Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setu... |
| CVE-2014-3654 | — | — | 1.8% | Nov 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satel... |
| CVE-2014-3683 | — | — | 4.6% | Nov 2, 2014 | Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to ca... |
| CVE-2014-3634 | — | — | 7.5% | Nov 2, 2014 | rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of serv... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now