2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8317 | — | — | 1.0% | Oct 17, 2014 | Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-... |
| CVE-2014-8316 | — | — | 2.8% | Oct 16, 2014 | XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remo... |
| CVE-2014-8315 | — | — | 1.5% | Oct 16, 2014 | polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connec... |
| CVE-2014-8314 | — | — | 2.2% | Oct 16, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA Developer Edition Revision 70 allow remote attackers to ... |
| CVE-2014-8313 | — | — | 2.1% | Oct 16, 2014 | Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execut... |
| CVE-2014-8312 | — | — | 2.1% | Oct 16, 2014 | Business Warehouse (BW) in SAP Netweaver AS ABAP 7.31 allows remote authenticated users to obtain sensitive information ... |
| CVE-2014-8311 | — | — | 1.8% | Oct 16, 2014 | SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information via an InfoStore query to a CORBA l... |
| CVE-2014-8310 | — | — | 2.9% | Oct 16, 2014 | The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server s... |
| CVE-2014-8309 | — | — | 1.7% | Oct 16, 2014 | SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt wit... |
| CVE-2014-8308 | — | — | 2.2% | Oct 16, 2014 | Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows re... |
| CVE-2014-8307 | — | — | 1.5% | Oct 16, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in skins/default/outline.tpl in C97net Cart Engine before 4.0 allow ... |
| CVE-2014-8306 | — | — | 1.2% | Oct 16, 2014 | SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attacke... |
| CVE-2014-8305 | — | — | 4.9% | Oct 16, 2014 | Open redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remot... |
| CVE-2014-8304 | — | — | 0.9% | Oct 16, 2014 | Cross-site scripting (XSS) vulnerability in In-Portal CMS 5.2.0 and earlier allows remote attackers to inject arbitrary ... |
| CVE-2014-8303 | — | — | 1.4% | Oct 16, 2014 | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4 and 6.0.x before 6.0.6 al... |
| CVE-2014-8302 | — | — | 0.8% | Oct 16, 2014 | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.6, and ... |
| CVE-2014-8301 | — | — | 0.9% | Oct 16, 2014 | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 5.0.x before 5.0.10 allows remote attackers ... |
| CVE-2014-8240 | — | — | 3.5% | Oct 16, 2014 | Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitra... |
| CVE-2014-7181 | — | — | 2.1% | Oct 16, 2014 | Cross-site scripting (XSS) vulnerability in the Max Foundry MaxButtons plugin before 1.26.1 for WordPress allows remote ... |
| CVE-2014-7138 | — | — | 2.4% | Oct 16, 2014 | Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote a... |
| CVE-2014-7050 | — | — | 0.3% | Oct 16, 2014 | The givenu give (aka com.givenu.give) application 1.5.3 for Android does not verify X.509 certificates from SSL servers,... |
| CVE-2014-7049 | — | — | 0.3% | Oct 16, 2014 | The SomTodo - Task/To-do widget (aka com.somcloud.somtodo) application 2.0.3 for Android does not verify X.509 certifica... |
| CVE-2014-7048 | — | — | 0.3% | Oct 16, 2014 | The Bear ID Lock (aka com.wBearIDLock) application 0.1 for Android does not verify X.509 certificates from SSL servers, ... |
| CVE-2014-7045 | — | — | 0.3% | Oct 16, 2014 | The Bust Out Bail (aka com.onesolutionapps.bustoutbailandroid) application 1.1 for Android does not verify X.509 certifi... |
| CVE-2014-7044 | — | — | 0.3% | Oct 16, 2014 | The Street Walker (aka kt.road.StreetWalker) application 0.0.1 for Android does not verify X.509 certificates from SSL s... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now