2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3147 | — | — | 0.8% | Oct 10, 2014 | Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote au... |
| CVE-2014-2649 | — | — | 6.4% | Oct 10, 2014 | Unspecified vulnerability in HP Operations Manager 9.20 on UNIX allows remote attackers to execute arbitrary code via un... |
| CVE-2014-2648 | — | — | 8.9% | Oct 10, 2014 | Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary co... |
| CVE-2014-2646 | — | — | 0.6% | Oct 10, 2014 | Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictio... |
| CVE-2014-2638 | — | — | 6.9% | Oct 10, 2014 | Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, ak... |
| CVE-2014-2637 | — | — | 6.9% | Oct 10, 2014 | Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, ak... |
| CVE-2014-2636 | — | — | 6.9% | Oct 10, 2014 | Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, ak... |
| CVE-2014-2635 | — | — | 6.9% | Oct 10, 2014 | Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, ak... |
| CVE-2014-8079 | — | — | 1.2% | Oct 9, 2014 | Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated... |
| CVE-2014-8078 | — | — | 1.0% | Oct 9, 2014 | Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1... |
| CVE-2014-8077 | — | — | 1.0% | Oct 9, 2014 | Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Dr... |
| CVE-2014-8076 | — | — | 0.9% | Oct 9, 2014 | Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenti... |
| CVE-2014-8075 | — | — | 0.9% | Oct 9, 2014 | Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticate... |
| CVE-2014-8068 | — | — | 1.8% | Oct 9, 2014 | Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote... |
| CVE-2014-7984 | — | — | 1.5% | Oct 8, 2014 | Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restric... |
| CVE-2014-7983 | — | — | 0.9% | Oct 8, 2014 | Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS 3.1.2 through 3.2.x before 3.2.3 allows remote at... |
| CVE-2014-7982 | — | — | 1.4% | Oct 8, 2014 | Cross-site scripting (XSS) vulnerability in Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers... |
| CVE-2014-7981 | — | — | 8.8% | Oct 8, 2014 | SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL... |
| CVE-2014-7296 | — | — | 1.7% | Oct 8, 2014 | The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which all... |
| CVE-2014-7231 | — | — | 0.5% | Oct 8, 2014 | The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2... |
| CVE-2014-7230 | — | — | 0.5% | Oct 8, 2014 | The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before... |
| CVE-2014-7229 | — | — | 1.3% | Oct 8, 2014 | Unspecified vulnerability in Joomla! before 2.5.4 before 2.5.26, 3.x before 3.2.6, and 3.3.x before 3.3.5 allows attacke... |
| CVE-2014-7203 | — | — | 1.9% | Oct 8, 2014 | libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attack... |
| CVE-2014-7202 | — | — | 2.0% | Oct 8, 2014 | stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade... |
| CVE-2014-6632 | — | — | 1.7% | Oct 8, 2014 | Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now