2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-8588SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL...
CVE-2014-8587SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SA...
CVE-2014-8586SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe...
CVE-2014-8585Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read...
CVE-2014-8584Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin befor...
CVE-2014-8339SQL injection vulnerability in midroll.php in Nuevolab Nuevoplayer for ClipShare 8.0 and earlier allows remote attackers...
CVE-2014-7176SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL...
CVE-2014-5387Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to exe...
CVE-2014-4311Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mai...
CVE-2014-0204OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the s...
CVE-2014-7228Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb...
CVE-2014-0490The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote...
CVE-2014-0489APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote atta...
CVE-2014-0488APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which...
CVE-2014-0487APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since he...
CVE-2014-8494ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe,...
CVE-2014-8350Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as de...
CVE-2014-8080The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attacker...
CVE-2014-5507iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local user...
CVE-2014-5272libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote a...
CVE-2014-5271Heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFMpeg before 1.1.14, 1.2.x ...
CVE-2014-3712Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setu...
CVE-2014-3654Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satel...
CVE-2014-3683Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to ca...
CVE-2014-3634rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of serv...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now