2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8088 | — | — | 2.5% | Oct 22, 2014 | The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.... |
| CVE-2014-7968 | — | — | 1.6% | Oct 22, 2014 | VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open. |
| CVE-2014-7183 | — | — | 2.3% | Oct 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attac... |
| CVE-2014-7182 | — | — | 2.5% | Oct 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remot... |
| CVE-2014-6387 | — | — | 2.1% | Oct 22, 2014 | gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will ... |
| CVE-2014-6352 | HIGH | 7.8 | 77.6% | Oct 22, 2014 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2... |
| CVE-2014-3677 | — | — | 2.7% | Oct 22, 2014 | Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers... |
| CVE-2014-3676 | — | — | 5.2% | Oct 22, 2014 | Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related... |
| CVE-2014-3675 | — | — | 2.7% | Oct 22, 2014 | Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet. |
| CVE-2014-4450 | — | — | 0.3% | Oct 22, 2014 | The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields wit... |
| CVE-2014-4449 | — | — | 0.7% | Oct 22, 2014 | iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-... |
| CVE-2014-4448 | — | — | 0.2% | Oct 22, 2014 | House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physic... |
| CVE-2014-3111 | — | — | 1.0% | Oct 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject ... |
| CVE-2014-2531 | — | — | 1.1% | Oct 21, 2014 | SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx... |
| CVE-2014-8380 | — | — | 3.3% | Oct 21, 2014 | Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML ... |
| CVE-2014-8379 | — | — | 0.9% | Oct 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA module before 7.x-1.5 for Drupal allow remote auth... |
| CVE-2014-8378 | — | — | 0.9% | Oct 21, 2014 | Cross-site scripting (XSS) vulnerability in the TableField module 7.x-2.x before 7.x-2.3 allows remote authenticated use... |
| CVE-2014-8377 | — | — | 1.4% | Oct 21, 2014 | Cross-site scripting (XSS) vulnerability in Webasyst Shop-Script 5.2.2.30933 allows remote attackers to inject arbitrary... |
| CVE-2014-8376 | — | — | 0.9% | Oct 21, 2014 | Cross-site scripting (XSS) vulnerability in the context administration sub-panel in the Site Banner module before 7.x-4.... |
| CVE-2014-7280 | — | — | 3.3% | Oct 21, 2014 | Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web s... |
| CVE-2014-5006 | — | — | 25.1% | Oct 21, 2014 | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers... |
| CVE-2014-5005 | — | — | 77.8% | Oct 21, 2014 | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers... |
| CVE-2014-4577 | — | — | 3.7% | Oct 21, 2014 | Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earli... |
| CVE-2014-4517 | — | — | 1.6% | Oct 21, 2014 | Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the CBI Referral Manager plugin 1.2.1 and earlier for... |
| CVE-2014-4514 | — | — | 1.7% | Oct 21, 2014 | Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and ear... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now