2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4814 | — | — | 1.6% | Oct 28, 2014 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0... |
| CVE-2014-4808 | — | — | 2.6% | Oct 28, 2014 | Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.... |
| CVE-2014-3293 | — | — | 1.7% | Oct 28, 2014 | Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows... |
| CVE-2014-8506 | — | — | 1.8% | Oct 28, 2014 | Multiple SQL injection vulnerabilities in Etiko CMS allow remote attackers to execute arbitrary SQL commands via the (1)... |
| CVE-2014-8505 | — | — | 1.4% | Oct 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Etiko CMS allow remote attackers to inject arbitrary web script o... |
| CVE-2014-4023 | — | — | 1.8% | Oct 28, 2014 | Cross-site scripting (XSS) vulnerability in tmui/dashboard/echo.jsp in the Configuration utility in F5 BIG-IP LTM, APM, ... |
| CVE-2014-4586 | — | — | 1.6% | Oct 27, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the wp-football plugin 1.1 and earlier for WordPress allow remote... |
| CVE-2014-8327 | — | — | 1.1% | Oct 27, 2014 | The fal_sftp extension before 0.2.6 for TYPO3 uses weak permissions for sFTP driver files and folders, which allows remo... |
| CVE-2014-3955 | — | — | 1.6% | Oct 27, 2014 | routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemo... |
| CVE-2014-3954 | — | — | 3.9% | Oct 27, 2014 | Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of servi... |
| CVE-2014-3711 | — | — | 1.6% | Oct 27, 2014 | namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vecto... |
| CVE-2014-2988 | — | — | 1.8% | Oct 27, 2014 | EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupwa... |
| CVE-2014-0136 | — | — | 1.6% | Oct 27, 2014 | The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remo... |
| CVE-2014-6635 | — | — | 1.4% | Oct 26, 2014 | Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.0 allows remote attackers to inject arbitrary web script or... |
| CVE-2014-5520 | — | — | 2.6% | Oct 26, 2014 | SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via ... |
| CVE-2014-5148 | — | — | 0.4% | Oct 26, 2014 | Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns... |
| CVE-2014-3520 | — | — | 1.9% | Oct 26, 2014 | OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticate... |
| CVE-2014-6037 | — | — | 84.2% | Oct 26, 2014 | Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8... |
| CVE-2014-6133 | — | — | 0.3% | Oct 26, 2014 | IBM API Management 3.x before 3.0.1.0 allows local users to obtain sensitive ciphertext information via unspecified vect... |
| CVE-2014-6099 | — | — | 1.3% | Oct 26, 2014 | The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechan... |
| CVE-2014-4812 | — | — | 0.5% | Oct 26, 2014 | The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, whi... |
| CVE-2014-2987 | — | — | 1.4% | Oct 26, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGro... |
| CVE-2014-3137 | — | — | 3.1% | Oct 25, 2014 | Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, whic... |
| CVE-2014-0476 | — | — | 3.8% | Oct 25, 2014 | The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a... |
| CVE-2014-5075 | — | — | 0.9% | Oct 25, 2014 | The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify t... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now