2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-8293 | — | — | 1.0% | Oct 15, 2014 | Cross-site scripting (XSS) vulnerability in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to inject arbitrary w... |
| CVE-2014-7206 | — | — | 0.4% | Oct 15, 2014 | The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the c... |
| CVE-2014-6312 | — | — | 4.2% | Oct 15, 2014 | Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before ... |
| CVE-2014-3681 | — | — | 2.1% | Oct 15, 2014 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to injec... |
| CVE-2014-3664 | — | — | 2.5% | Oct 15, 2014 | Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with ... |
| CVE-2014-3593 | — | — | 1.4% | Oct 15, 2014 | Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitr... |
| CVE-2014-2927 | — | — | 7.9% | Oct 15, 2014 | The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before... |
| CVE-2014-2576 | — | — | 2.0% | Oct 15, 2014 | plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name field... |
| CVE-2014-2022 | — | — | 2.7% | Oct 15, 2014 | SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier a... |
| CVE-2014-1830 | — | — | 2.0% | Oct 15, 2014 | Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-A... |
| CVE-2014-1829 | — | — | 2.2% | Oct 15, 2014 | Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorizatio... |
| CVE-2014-6952 | — | — | 0.3% | Oct 15, 2014 | The Manga Facts (aka app.mangafacts.ar) application 1.0 for Android does not verify X.509 certificates from SSL servers,... |
| CVE-2014-6951 | — | — | 0.3% | Oct 15, 2014 | The OneFile Ignite (aka uk.co.onefile.ignite) application 1.19 for Android does not verify X.509 certificates from SSL s... |
| CVE-2014-6950 | — | — | 0.3% | Oct 15, 2014 | The Mt. Airy News (aka com.soln.SBE4A803AD6430A6E9DBA5688AA644148) application 1.0069.b0069 for Android does not verify ... |
| CVE-2014-6949 | — | — | 0.3% | Oct 15, 2014 | The Akne Ernahrung (aka com.rareartifact.akneernahrung72010074) application 1.0 for Android does not verify X.509 certif... |
| CVE-2014-6948 | — | — | 0.3% | Oct 15, 2014 | The TH3 professional Al Mohtarif (aka com.th3professional.almohtarif) application 1.0 for Android does not verify X.509 ... |
| CVE-2014-6947 | — | — | 0.3% | Oct 15, 2014 | The Archie Comics (aka com.iversecomics.archie.android) application 1.07 for Android does not verify X.509 certificates ... |
| CVE-2014-6946 | — | — | 0.3% | Oct 15, 2014 | The Re:kyu (aka com.appzone619) application 1.0 for Android does not verify X.509 certificates from SSL servers, which a... |
| CVE-2014-6945 | — | — | 0.3% | Oct 15, 2014 | The Neeku Naaku Dash Dash (aka com.dakshaa.nndd) application 1.0 for Android does not verify X.509 certificates from SSL... |
| CVE-2014-6944 | — | — | 0.3% | Oct 15, 2014 | The mitfahrgelegenheit.at (aka com.carpooling.android.at) application 2.3.0 for Android does not verify X.509 certificat... |
| CVE-2014-6943 | — | — | 0.3% | Oct 15, 2014 | The Konigsleiten (aka com.knigsleiten) application 1.0 for Android does not verify X.509 certificates from SSL servers, ... |
| CVE-2014-6942 | — | — | 0.3% | Oct 15, 2014 | The Alisha Marie (Unofficial) (aka com.automon.ay.alisha.marie) application 1.4.0.6 for Android does not verify X.509 ce... |
| CVE-2014-4148 | HIGH | 8.8 | 50.7% | Oct 15, 2014 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a... |
| CVE-2014-4141 | — | — | 30.5% | Oct 15, 2014 | Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ... |
| CVE-2014-4140 | — | — | 20.7% | Oct 15, 2014 | Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted w... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now