2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2632 | — | — | 13.3% | Aug 23, 2014 | Unspecified vulnerability in the WebTier component in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote att... |
| CVE-2014-5120 | — | — | 16.9% | Aug 23, 2014 | gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 ... |
| CVE-2014-3597 | — | — | 15.4% | Aug 23, 2014 | Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16... |
| CVE-2014-3587 | — | — | 20.2% | Aug 23, 2014 | Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component... |
| CVE-2014-5243 | — | — | 1.8% | Aug 22, 2014 | MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME prote... |
| CVE-2014-5242 | — | — | 2.1% | Aug 22, 2014 | Cross-site scripting (XSS) vulnerability in mediawiki.page.image.pagination.js in MediaWiki 1.22.x before 1.22.9 and 1.2... |
| CVE-2014-5241 | — | — | 0.8% | Aug 22, 2014 | The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, a... |
| CVE-2014-3563 | — | — | 0.4% | Aug 22, 2014 | Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified i... |
| CVE-2014-5396 | — | — | 2.1% | Aug 22, 2014 | The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for t... |
| CVE-2014-5368 | — | — | 18.8% | Aug 22, 2014 | Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Sour... |
| CVE-2014-5338 | — | — | 1.7% | Aug 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 befo... |
| CVE-2014-5262 | — | — | 2.3% | Aug 22, 2014 | SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote ... |
| CVE-2014-5261 | — | — | 10.8% | Aug 22, 2014 | The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary ... |
| CVE-2014-5246 | — | — | 12.5% | Aug 22, 2014 | The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication... |
| CVE-2014-5149 | — | — | 0.4% | Aug 22, 2014 | Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, whi... |
| CVE-2014-5146 | — | — | 0.4% | Aug 22, 2014 | Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assiste... |
| CVE-2014-5122 | — | — | 2.1% | Aug 22, 2014 | Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web ... |
| CVE-2014-5121 | — | — | 2.4% | Aug 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject ar... |
| CVE-2014-5097 | — | — | 2.3% | Aug 22, 2014 | Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execut... |
| CVE-2014-4197 | — | — | 1.3% | Aug 22, 2014 | Multiple SQL injection vulnerabilities in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allow remote attackers to execute... |
| CVE-2014-3594 | — | — | 2.1% | Aug 22, 2014 | Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2... |
| CVE-2014-3525 | — | — | 4.5% | Aug 22, 2014 | Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unkno... |
| CVE-2014-0232 | — | — | 8.2% | Aug 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz ... |
| CVE-2014-5274 | — | — | 1.0% | Aug 22, 2014 | Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x befor... |
| CVE-2014-5273 | — | — | 1.7% | Aug 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now