2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8577 | — | — | 4.3% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we... |
| CVE-2014-8509 | — | — | 5.1% | Oct 31, 2014 | The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code ... |
| CVE-2014-8495 | — | — | 1.6% | Oct 31, 2014 | Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached applic... |
| CVE-2014-8399 | — | — | 0.4% | Oct 31, 2014 | The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a de... |
| CVE-2014-8334 | — | — | 3.5% | Oct 31, 2014 | The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute a... |
| CVE-2014-8333 | — | — | 2.0% | Oct 31, 2014 | The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of ser... |
| CVE-2014-8082 | — | — | 2.6% | Oct 31, 2014 | lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via u... |
| CVE-2014-8081 | — | — | 4.2% | Oct 31, 2014 | lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks... |
| CVE-2014-7987 | — | — | 2.2% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script ... |
| CVE-2014-7986 | — | — | 2.9% | Oct 31, 2014 | install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the ins... |
| CVE-2014-7985 | — | — | 5.0% | Oct 31, 2014 | Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local... |
| CVE-2014-7177 | — | — | 3.3% | Oct 31, 2014 | XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary ... |
| CVE-2014-3708 | — | — | 2.8% | Oct 31, 2014 | OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denia... |
| CVE-2014-2336 | — | — | 1.8% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and ... |
| CVE-2014-2335 | — | — | 1.1% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allo... |
| CVE-2014-2334 | — | — | 1.2% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiAnalyzer before 5.0.7 all... |
| CVE-2014-6150 | — | — | 0.9% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.0 through ... |
| CVE-2014-6148 | — | — | 1.0% | Oct 31, 2014 | IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2... |
| CVE-2014-6101 | — | — | 1.2% | Oct 31, 2014 | Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manager (BPM) Advanced 7.... |
| CVE-2014-3375 | — | — | 2.0% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the CCM Service interface in the Server in Cisco Unified Communic... |
| CVE-2014-3374 | — | — | 2.0% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the CCM admin interface in the Server in Cisco Unified Communicat... |
| CVE-2014-3373 | — | — | 2.0% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the CCM Dialed Number Analyzer interface in the Server in Cisco U... |
| CVE-2014-3372 | — | — | 2.0% | Oct 31, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the CCM reports interface in the Server in Cisco Unified Communic... |
| CVE-2014-3366 | — | — | 1.6% | Oct 31, 2014 | SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote au... |
| CVE-2014-3684 | — | — | 2.8% | Oct 30, 2014 | The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manage... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now