2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6631 | — | — | 0.9% | Oct 8, 2014 | Cross-site scripting (XSS) vulnerability in com_media in Joomla! 3.2.x before 3.2.5 and 3.3.x before 3.3.4 allows remote... |
| CVE-2014-5376 | — | — | 1.7% | Oct 8, 2014 | Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0, when a pre-generated key is used, does not validate that the re... |
| CVE-2014-5375 | — | — | 1.7% | Oct 8, 2014 | The server in Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 does not properly validate the message owner match... |
| CVE-2014-5300 | — | — | 7.4% | Oct 8, 2014 | Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersona... |
| CVE-2014-3641 | — | — | 1.9% | Oct 8, 2014 | The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to o... |
| CVE-2014-7980 | — | — | 0.9% | Oct 8, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x befo... |
| CVE-2014-7979 | — | — | 0.9% | Oct 8, 2014 | Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authent... |
| CVE-2014-7978 | — | — | 0.9% | Oct 8, 2014 | Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authen... |
| CVE-2014-7205 | — | — | 78.6% | Oct 8, 2014 | Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t... |
| CVE-2014-7185 | — | — | 5.1% | Oct 8, 2014 | Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive informa... |
| CVE-2014-6394 | — | — | 4.3% | Oct 8, 2014 | visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the docu... |
| CVE-2014-5308 | — | — | 3.5% | Oct 8, 2014 | Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm... |
| CVE-2014-7967 | — | — | 0.6% | Oct 8, 2014 | Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allo... |
| CVE-2014-3200 | — | — | 1.4% | Oct 8, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service ... |
| CVE-2014-3199 | — | — | 1.3% | Oct 8, 2014 | The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome bef... |
| CVE-2014-3198 | — | — | 1.3% | Oct 8, 2014 | The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101... |
| CVE-2014-3197 | — | — | 1.0% | Oct 8, 2014 | The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google C... |
| CVE-2014-3196 | — | — | 1.0% | Oct 8, 2014 | base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only ... |
| CVE-2014-3195 | — | — | 1.2% | Oct 8, 2014 | Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as ... |
| CVE-2014-3194 | — | — | 1.1% | Oct 8, 2014 | Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attac... |
| CVE-2014-3193 | — | — | 1.7% | Oct 8, 2014 | The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101... |
| CVE-2014-3192 | — | — | 1.7% | Oct 8, 2014 | Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.c... |
| CVE-2014-3191 | — | — | 1.4% | Oct 8, 2014 | Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a... |
| CVE-2014-3190 | — | — | 1.4% | Oct 8, 2014 | Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google C... |
| CVE-2014-3189 | — | — | 1.2% | Oct 8, 2014 | The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 do... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now