2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-0222Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denia...
CVE-2014-0182Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote att...
CVE-2014-8474CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to read arbitrary files, send HTTP requests...
CVE-2014-8473Cross-site request forgery (CSRF) vulnerability in CA Cloud Service Management (CSM) before Summer 2014 allows remote at...
CVE-2014-8472CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Pro...
CVE-2014-8471CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to conduct replay attacks via unspecified v...
CVE-2014-7875Unspecified vulnerability on the HP LaserJet CM3530 Multifunction Printer CC519A and CC520A with firmware before 53.236....
CVE-2014-6130The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP sessio...
CVE-2014-8593Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary ...
CVE-2014-4974The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212...
CVE-2014-3660parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disab...
CVE-2014-8592Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a d...
CVE-2014-8591Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 and 7.3, allows rem...
CVE-2014-8590XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allow...
CVE-2014-8589Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (...
CVE-2014-8588SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL...
CVE-2014-8587SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SA...
CVE-2014-8586SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe...
CVE-2014-8585Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read...
CVE-2014-8584Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin befor...
CVE-2014-8339SQL injection vulnerability in midroll.php in Nuevolab Nuevoplayer for ClipShare 8.0 and earlier allows remote attackers...
CVE-2014-7176SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL...
CVE-2014-5387Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to exe...
CVE-2014-4311Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mai...
CVE-2014-0204OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the s...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now