2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6938 | — | — | 0.3% | Oct 11, 2014 | The Apostilas musicais (aka com.apostilas) application 1.0 for Android does not verify X.509 certificates from SSL serve... |
| CVE-2014-6937 | — | — | 0.3% | Oct 11, 2014 | The China CITIC Bank Credit Card (aka com.citiccard.mobilebank) application 3.3.6 for Android does not verify X.509 cert... |
| CVE-2014-6936 | — | — | 0.3% | Oct 11, 2014 | The IDS 2013 (aka de.mobileeventguide.ids2013) application 1.21 for Android does not verify X.509 certificates from SSL ... |
| CVE-2014-6935 | — | — | 0.3% | Oct 11, 2014 | The ColorMania - Color Quiz Game (aka com.ColormaniaColoringGames) application 1.4 for Android does not verify X.509 cer... |
| CVE-2014-6934 | — | — | 0.3% | Oct 11, 2014 | The Physics Chemistry Biology Quiz (aka com.pdevsmcqs.pcbmcqseries) application 1.8 for Android does not verify X.509 ce... |
| CVE-2014-6904 | — | — | 0.3% | Oct 11, 2014 | The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates fr... |
| CVE-2014-6891 | — | — | 0.3% | Oct 11, 2014 | The Vodafone Avantaj Cepte (aka com.vodafone.avantajcepte.main) application 1.4 for Android does not verify X.509 certif... |
| CVE-2014-6887 | — | — | 0.3% | Oct 11, 2014 | The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SS... |
| CVE-2014-7201 | — | — | 2.3% | Oct 10, 2014 | Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (d... |
| CVE-2014-7200 | — | — | 3.2% | Oct 10, 2014 | Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extensi... |
| CVE-2014-7139 | — | — | 2.0% | Oct 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Contact Form DB (aka CFDB and contact-form-7-to-database-exte... |
| CVE-2014-6315 | — | — | 2.4% | Oct 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPr... |
| CVE-2014-6243 | — | — | 2.1% | Oct 10, 2014 | Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote att... |
| CVE-2014-4737 | — | — | 1.9% | Oct 10, 2014 | Cross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7 allows remote attackers to inject arbitrary web... |
| CVE-2014-4313 | — | — | 2.2% | Oct 10, 2014 | SQL injection vulnerability in Epicor Procurement before 7.4 SP2 allows remote attackers to execute arbitrary SQL comman... |
| CVE-2014-4312 | — | — | 4.2% | Oct 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote ... |
| CVE-2014-3678 | — | — | 1.8% | Oct 10, 2014 | Cross-site scripting (XSS) vulnerability in the Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to i... |
| CVE-2014-4874 | — | — | 7.6% | Oct 10, 2014 | BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment... |
| CVE-2014-4873 | — | — | 2.9% | Oct 10, 2014 | SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to ... |
| CVE-2014-4872 | — | — | 80.1% | Oct 10, 2014 | BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit... |
| CVE-2014-4867 | — | — | 0.3% | Oct 10, 2014 | Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain p... |
| CVE-2014-4761 | — | — | 1.6% | Oct 10, 2014 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.... |
| CVE-2014-3581 | — | — | 13.2% | Oct 10, 2014 | The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server bef... |
| CVE-2014-3402 | — | — | 1.3% | Oct 10, 2014 | The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier ... |
| CVE-2014-3394 | — | — | 1.0% | Oct 10, 2014 | The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now