2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3077 | — | — | 0.3% | Sep 15, 2014 | IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth passwo... |
| CVE-2014-2377 | — | — | 1.8% | Sep 15, 2014 | Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to disco... |
| CVE-2014-2376 | — | — | 2.0% | Sep 15, 2014 | SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier a... |
| CVE-2014-2375 | — | — | 2.3% | Sep 15, 2014 | Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read ... |
| CVE-2014-0993 | — | — | 5.7% | Sep 15, 2014 | Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero ... |
| CVE-2014-5888 | — | — | 0.3% | Sep 12, 2014 | The SLOTS: Bible Slots Free (aka com.topfreegames.topbibleslots) application 1.122 for Android does not verify X.509 cer... |
| CVE-2014-5887 | — | — | 0.3% | Sep 12, 2014 | The Yell Local Search (aka com.yell.launcher2) application 4.2.1.4 for Android does not verify X.509 certificates from S... |
| CVE-2014-5886 | — | — | 0.3% | Sep 12, 2014 | The iVysilani ceske televize (aka cz.motion.ivysilani) application 1.6 for Android does not verify X.509 certificates fr... |
| CVE-2014-5885 | — | — | 0.3% | Sep 12, 2014 | The Disaster Alert (aka disasterAlert.PDC) application 3.2 for Android does not verify X.509 certificates from SSL serve... |
| CVE-2014-5884 | — | — | 0.3% | Sep 12, 2014 | The 1&1 Online Storage (aka de.einsundeins.smartdrive) application 5.0.11 for Android does not verify X.509 certificates... |
| CVE-2014-5883 | — | — | 0.3% | Sep 12, 2014 | The 7-ELEVEN (aka ecowork.seven) application 2.08.000 for Android does not verify X.509 certificates from SSL servers, w... |
| CVE-2014-6270 | — | — | 23.3% | Sep 12, 2014 | Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, al... |
| CVE-2014-5441 | — | — | 1.9% | Sep 12, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.... |
| CVE-2014-5440 | — | — | 2.1% | Sep 12, 2014 | SQL injection vulnerability in Login.aspx in MPEX Business Solutions MX-SmartTimer before 13.19.18 allows remote attacke... |
| CVE-2014-5259 | — | — | 2.0% | Sep 12, 2014 | Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and... |
| CVE-2014-4735 | — | — | 1.9% | Sep 12, 2014 | Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier allows remote attackers to inject arbitrary web scr... |
| CVE-2014-2009 | — | — | 7.4% | Sep 12, 2014 | The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path... |
| CVE-2014-2008 | — | — | 2.6% | Sep 12, 2014 | SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attacker... |
| CVE-2014-4811 | — | — | 2.7% | Sep 12, 2014 | IBM Storwize 3500, 3700, 5000, and 7000 devices and SAN Volume Controller 6.x and 7.x before 7.2.0.8 allow remote attack... |
| CVE-2014-4792 | — | — | 1.9% | Sep 12, 2014 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 through 8... |
| CVE-2014-4762 | — | — | 1.4% | Sep 12, 2014 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF13 and 8.5.0 before CF02 allows... |
| CVE-2014-3363 | — | — | 1.5% | Sep 12, 2014 | Cross-site scripting (XSS) vulnerability in the web framework in Cisco Unified Communications Manager (UCM) 9.1(2.10000.... |
| CVE-2014-3362 | — | — | 2.8% | Sep 12, 2014 | Memory leak in Cisco TelePresence System Edge MXP Series Software F9.3.3 and earlier allows remote attackers to cause a ... |
| CVE-2014-3342 | — | — | 1.1% | Sep 12, 2014 | The CLI in Cisco IOS XR allows remote authenticated users to obtain sensitive information via unspecified commands, aka ... |
| CVE-2014-3092 | — | — | 1.7% | Sep 12, 2014 | IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now