2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7217 | — | — | 1.6% | Oct 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.... |
| CVE-2014-6905 | — | — | 0.3% | Oct 3, 2014 | The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certif... |
| CVE-2014-6903 | — | — | 0.3% | Oct 3, 2014 | The Gulf Power Mobile Bill Pay (aka com.tionetworks.gulf) application 1 for Android does not verify X.509 certificates f... |
| CVE-2014-6902 | — | — | 0.3% | Oct 3, 2014 | The Anjuke (aka com.anjuke.android.app) application 7.1.7 for Android does not verify X.509 certificates from SSL server... |
| CVE-2014-6901 | — | — | 0.3% | Oct 3, 2014 | The RADIOS DEL ECUADOR (aka com.nobexinc.wls_87612622.rc) application 3.2.4 for Android does not verify X.509 certificat... |
| CVE-2014-6900 | — | — | 0.3% | Oct 3, 2014 | The EAGE Amsterdam 2014 (aka com.coreapps.android.followme.eage_2014) application 6.1.1.2 for Android does not verify X.... |
| CVE-2014-6899 | — | — | 0.3% | Oct 3, 2014 | The Jazeera Airways (aka com.winit.jazeeraairways) application 2.7 for Android does not verify X.509 certificates from S... |
| CVE-2014-6898 | — | — | 0.3% | Oct 3, 2014 | The Boopsie MyLibrary (aka com.bredir.boopsie.mylibrary) application 4.5.110 for Android does not verify X.509 certifica... |
| CVE-2014-6897 | — | — | 0.3% | Oct 3, 2014 | The Skyrim Map (aka com.neko.skyrimmap) application 2.1 for Android does not verify X.509 certificates from SSL servers,... |
| CVE-2014-6896 | — | — | 0.3% | Oct 3, 2014 | The Yik Yak (aka com.yik.yak) application 2.0.002 for Android does not verify X.509 certificates from SSL servers, which... |
| CVE-2014-6895 | — | — | 0.3% | Oct 3, 2014 | The Throne Rush (aka com.progrestar.bft) application 2.3.10 for Android does not verify X.509 certificates from SSL serv... |
| CVE-2014-6894 | — | — | 0.3% | Oct 3, 2014 | The Lucktastic (aka com.lucktastic.scratch) application 1.2.6 for Android does not verify X.509 certificates from SSL se... |
| CVE-2014-6079 | — | — | 1.4% | Oct 3, 2014 | Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x be... |
| CVE-2014-4823 | — | — | 2.8% | Oct 3, 2014 | The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-I... |
| CVE-2014-4809 | — | — | 1.5% | Oct 3, 2014 | The WebSEAL component in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WG... |
| CVE-2014-7188 | — | — | 0.9% | Oct 2, 2014 | The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC... |
| CVE-2014-7158 | — | — | 1.1% | Oct 2, 2014 | Cross-site request forgery (CSRF) vulnerability in Exinda WAN Optimization Suite 7.0.0 (2160) allows remote attackers to... |
| CVE-2014-7157 | — | — | 1.9% | Oct 2, 2014 | Cross-site scripting (XSS) vulnerability in Exinda WAN Optimization Suite 7.0.0 (2160) allows remote attackers to inject... |
| CVE-2014-7156 | — | — | 0.8% | Oct 2, 2014 | The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor ... |
| CVE-2014-7155 | — | — | 1.0% | Oct 2, 2014 | The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervis... |
| CVE-2014-7154 | — | — | 0.7% | Oct 2, 2014 | Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for ... |
| CVE-2014-7144 | — | — | 1.9% | Oct 2, 2014 | OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certificat... |
| CVE-2014-6414 | — | — | 2.1% | Oct 2, 2014 | OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attr... |
| CVE-2014-6242 | — | — | 4.2% | Oct 2, 2014 | Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow ... |
| CVE-2014-3621 | — | — | 2.1% | Oct 2, 2014 | The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now