2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0619 | — | — | 0.6% | Oct 23, 2014 | Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code an... |
| CVE-2014-4766 | — | — | 1.4% | Oct 23, 2014 | IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading a... |
| CVE-2014-3829 | — | — | 81.0% | Oct 23, 2014 | displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot... |
| CVE-2014-3828 | — | — | 72.7% | Oct 23, 2014 | Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3... |
| CVE-2014-8764 | — | — | 1.7% | Oct 22, 2014 | DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass... |
| CVE-2014-8763 | — | — | 2.5% | Oct 22, 2014 | DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass auth... |
| CVE-2014-8762 | — | — | 2.4% | Oct 22, 2014 | The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a craf... |
| CVE-2014-8761 | — | — | 1.6% | Oct 22, 2014 | inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attack... |
| CVE-2014-8381 | — | — | 1.9% | Oct 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Megapolis.Portal Manager allow remote attackers to inject arbitra... |
| CVE-2014-8325 | — | — | 1.8% | Oct 22, 2014 | The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 allows remote attackers to cause a denia... |
| CVE-2014-8088 | — | — | 2.5% | Oct 22, 2014 | The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.... |
| CVE-2014-7968 | — | — | 1.6% | Oct 22, 2014 | VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open. |
| CVE-2014-7183 | — | — | 2.3% | Oct 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attac... |
| CVE-2014-7182 | — | — | 2.5% | Oct 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remot... |
| CVE-2014-6387 | — | — | 2.1% | Oct 22, 2014 | gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will ... |
| CVE-2014-3677 | — | — | 2.7% | Oct 22, 2014 | Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers... |
| CVE-2014-3676 | — | — | 5.2% | Oct 22, 2014 | Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related... |
| CVE-2014-3675 | — | — | 2.7% | Oct 22, 2014 | Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet. |
| CVE-2014-4450 | — | — | 0.3% | Oct 22, 2014 | The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields wit... |
| CVE-2014-4449 | — | — | 0.7% | Oct 22, 2014 | iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-... |
| CVE-2014-4448 | — | — | 0.2% | Oct 22, 2014 | House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physic... |
| CVE-2014-3111 | — | — | 1.0% | Oct 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject ... |
| CVE-2014-2531 | — | — | 1.1% | Oct 21, 2014 | SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx... |
| CVE-2014-8380 | — | — | 3.3% | Oct 21, 2014 | Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML ... |
| CVE-2014-8379 | — | — | 0.9% | Oct 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA module before 7.x-1.5 for Drupal allow remote auth... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now