2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8669 | — | — | 5.5% | Nov 6, 2014 | The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code ... |
| CVE-2014-8668 | — | — | 1.3% | Nov 6, 2014 | SQL injection vulnerability in SAP Contract Accounting allows remote attackers to execute arbitrary SQL commands via uns... |
| CVE-2014-8667 | — | — | 0.9% | Nov 6, 2014 | Cross-site scripting (XSS) vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to inject a... |
| CVE-2014-8666 | — | — | 1.2% | Nov 6, 2014 | The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allow... |
| CVE-2014-8665 | — | — | 1.2% | Nov 6, 2014 | The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading u... |
| CVE-2014-8664 | — | — | 1.3% | Nov 6, 2014 | SQL injection vulnerability in Product Safety (EHS-SAF) component in SAP Environment, Health, and Safety Management allo... |
| CVE-2014-8663 | — | — | 1.2% | Nov 6, 2014 | SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to ex... |
| CVE-2014-8662 | — | — | 1.3% | Nov 6, 2014 | Unspecified vulnerability in SAP Payroll Process allows remote attackers to cause a denial of service via vectors relate... |
| CVE-2014-8661 | — | — | 2.8% | Nov 6, 2014 | The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors. |
| CVE-2014-8660 | — | — | 0.4% | Nov 6, 2014 | SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors. |
| CVE-2014-8659 | — | — | 1.9% | Nov 6, 2014 | Directory traversal vulnerability in SAP Environment, Health, and Safety allows remote attackers to read arbitrary files... |
| CVE-2014-8658 | — | — | 1.8% | Nov 6, 2014 | Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme 3.x before 3.5.13 and 4.x before 4.0.12 for Confl... |
| CVE-2014-8657 | — | — | 6.8% | Nov 6, 2014 | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r... |
| CVE-2014-8656 | — | — | 10.9% | Nov 6, 2014 | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a d... |
| CVE-2014-8655 | — | — | 7.4% | Nov 6, 2014 | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r... |
| CVE-2014-8654 | — | — | 2.9% | Nov 6, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wirele... |
| CVE-2014-8653 | — | — | 3.5% | Nov 6, 2014 | Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 wit... |
| CVE-2014-8508 | — | — | 1.0% | Nov 6, 2014 | Cross-site scripting (XSS) vulnerability in s_network.asp in the Denon AVR-3313CI audio/video receiver allows remote att... |
| CVE-2014-8483 | — | — | 3.5% | Nov 6, 2014 | The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (... |
| CVE-2014-8352 | — | — | 1.5% | Nov 6, 2014 | Cross-site scripting (XSS) vulnerability in json.php in French National Commission on Informatics and Liberty (aka CNIL)... |
| CVE-2014-8351 | — | — | 1.7% | Nov 6, 2014 | SQL injection vulnerability in info.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz be... |
| CVE-2014-7959 | — | — | 2.1% | Nov 6, 2014 | SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPres... |
| CVE-2014-7958 | — | — | 2.5% | Nov 6, 2014 | Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1... |
| CVE-2014-5257 | — | — | 1.9% | Nov 6, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Forma Lms before 1.2.1 p01 allow remote attackers to inject arbit... |
| CVE-2014-4664 | — | — | 2.3% | Nov 6, 2014 | Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attac... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now