2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1929 | — | — | 0.4% | Oct 25, 2014 | python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "op... |
| CVE-2014-1928 | — | — | 0.6% | Oct 25, 2014 | The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attac... |
| CVE-2014-1927 | — | — | 3.4% | Oct 25, 2014 | The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers... |
| CVE-2014-3636 | — | — | 0.5% | Oct 25, 2014 | D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prev... |
| CVE-2014-6611 | — | — | 1.0% | Oct 25, 2014 | The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and b... |
| CVE-2014-6152 | — | — | 0.9% | Oct 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Integrated Portal (TIP) 2.2.x allow remote authenticat... |
| CVE-2014-6151 | — | — | 1.0% | Oct 25, 2014 | CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arb... |
| CVE-2014-4624 | — | — | 3.3% | Oct 25, 2014 | EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authenticatio... |
| CVE-2014-4623 | — | — | 1.6% | Oct 25, 2014 | EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Ha... |
| CVE-2014-4620 | — | — | 0.5% | Oct 25, 2014 | The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, st... |
| CVE-2014-3409 | — | — | 1.0% | Oct 25, 2014 | The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13... |
| CVE-2014-8760 | — | — | 1.3% | Oct 25, 2014 | ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to ... |
| CVE-2014-7180 | — | — | 0.5% | Oct 25, 2014 | Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and... |
| CVE-2014-6251 | — | — | 1.0% | Oct 25, 2014 | Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a ... |
| CVE-2014-6230 | — | — | 2.4% | Oct 25, 2014 | WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the ... |
| CVE-2014-3604 | — | — | 0.9% | Oct 25, 2014 | Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domai... |
| CVE-2014-2021 | — | — | 3.4% | Oct 25, 2014 | Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 a... |
| CVE-2014-8346 | — | — | 1.7% | Oct 24, 2014 | The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a net... |
| CVE-2014-7298 | — | — | 0.4% | Oct 24, 2014 | adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX ... |
| CVE-2014-8073 | — | — | 1.1% | Oct 23, 2014 | Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the ... |
| CVE-2014-8072 | — | — | 1.8% | Oct 23, 2014 | The administration module in OpenMRS 2.1 Standalone Edition allows remote authenticated users to obtain read access via ... |
| CVE-2014-8071 | — | — | 1.9% | Oct 23, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject a... |
| CVE-2014-7292 | — | — | 2.0% | Oct 23, 2014 | Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.1612... |
| CVE-2014-7281 | — | — | 2.6% | Oct 23, 2014 | Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a... |
| CVE-2014-2230 | — | — | 2.0% | Oct 23, 2014 | Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now