2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3985 | — | — | 3.3% | Sep 11, 2014 | The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) ... |
| CVE-2014-3740 | — | — | 3.4% | Sep 11, 2014 | Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbi... |
| CVE-2014-3609 | — | — | 56.2% | Sep 11, 2014 | HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (... |
| CVE-2014-5882 | — | — | 0.3% | Sep 11, 2014 | The Homoo Ijiri (aka jp.co.applica) application 3.7 for Android does not verify X.509 certificates from SSL servers, whi... |
| CVE-2014-5881 | — | — | 0.4% | Sep 11, 2014 | The Yahoo! Japan Box (aka jp.co.yahoo.android.ybox) application 1.5.1 for Android does not verify X.509 certificates fro... |
| CVE-2014-5879 | — | — | 0.3% | Sep 11, 2014 | The tvguide (aka kenneth.tvguide) application 1.9.14 for Android does not verify X.509 certificates from SSL servers, wh... |
| CVE-2014-6043 | — | — | 12.8% | Sep 11, 2014 | ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database ... |
| CVE-2014-5460 | — | — | 70.9% | Sep 11, 2014 | Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot... |
| CVE-2014-5393 | — | — | 2.6% | Sep 11, 2014 | Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.... |
| CVE-2014-5391 | — | — | 2.2% | Sep 11, 2014 | Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246... |
| CVE-2014-5129 | — | — | 2.3% | Sep 11, 2014 | Cross-site scripting (XSS) vulnerability in Avolve Software ProjectDox 8.1 allows remote attackers to inject arbitrary w... |
| CVE-2014-6241 | — | — | 1.3% | Sep 11, 2014 | SQL injection vulnerability in the wt_directory extension before 1.4.1 for TYPO3 allows remote attackers to execute arbi... |
| CVE-2014-6240 | — | — | 0.9% | Sep 11, 2014 | Cross-site scripting (XSS) vulnerability in the Google Sitemap (weeaar_googlesitemap) extension 0.4.3 and earlier for TY... |
| CVE-2014-6239 | — | — | 1.2% | Sep 11, 2014 | SQL injection vulnerability in the Address visualization with Google Maps (st_address_map) extension before 0.3.6 allows... |
| CVE-2014-6238 | — | — | 1.1% | Sep 11, 2014 | Cross-site scripting (XSS) vulnerability in the Akronymmanager (aka SB Folderdownload) extension 0.5.0 and earlier for T... |
| CVE-2014-6237 | — | — | 0.9% | Sep 11, 2014 | Cross-site scripting (XSS) vulnerability in the News Pack extension 0.1.0 and earlier for TYPO3 allows remote authentica... |
| CVE-2014-6236 | — | — | 2.7% | Sep 11, 2014 | Unspecified vulnerability in the LumoNet PHP Include (lumophpinclude) extension before 1.2.1 for TYPO3 allows remote att... |
| CVE-2014-6235 | — | — | 5.6% | Sep 11, 2014 | Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary... |
| CVE-2014-6234 | — | — | 1.2% | Sep 11, 2014 | Cross-site scripting (XSS) vulnerability in the Open Graph protocol (jh_opengraphprotocol) extension before 1.0.2 for TY... |
| CVE-2014-6233 | — | — | 1.3% | Sep 11, 2014 | SQL injection vulnerability in the Flat Manager (flatmgr) extension before 2.7.10 for TYPO3 allows remote attackers to e... |
| CVE-2014-6232 | — | — | 1.1% | Sep 11, 2014 | Unspecified vulnerability in the LDAP (eu_ldap) extension before 2.8.18 for TYPO3 allows remote authenticated users to o... |
| CVE-2014-6231 | — | — | 2.7% | Sep 11, 2014 | Unspecified vulnerability in the CWT Frontend Edit (cwt_feedit) extension before 1.2.5 for TYPO3 allows remote authentic... |
| CVE-2014-6070 | — | — | 3.6% | Sep 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject... |
| CVE-2014-5519 | — | — | 65.0% | Sep 11, 2014 | The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a dev... |
| CVE-2014-2223 | — | — | 10.0% | Sep 11, 2014 | Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now