2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3464 | — | — | 1.1% | Aug 19, 2014 | The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2... |
| CVE-2014-5333 | — | — | 3.5% | Aug 19, 2014 | Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Ad... |
| CVE-2014-3906 | — | — | 1.2% | Aug 19, 2014 | SQL injection vulnerability in OSK Advance-Flow 4.41 and earlier and Advance-Flow Forms 4.41 and earlier allows remote a... |
| CVE-2014-3903 | — | — | 1.5% | Aug 19, 2014 | Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated ... |
| CVE-2014-3341 | — | — | 4.7% | Aug 19, 2014 | The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages ... |
| CVE-2014-5266 | — | — | 24.4% | Aug 18, 2014 | The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, doe... |
| CVE-2014-5265 | — | — | 3.1% | Aug 18, 2014 | The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, per... |
| CVE-2014-5240 | — | — | 2.2% | Aug 18, 2014 | Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabl... |
| CVE-2014-5207 | — | — | 0.9% | Aug 18, 2014 | fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOE... |
| CVE-2014-5206 | — | — | 0.4% | Aug 18, 2014 | The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit... |
| CVE-2014-5205 | — | — | 1.8% | Aug 18, 2014 | wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and ui... |
| CVE-2014-5204 | — | — | 1.8% | Aug 18, 2014 | wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on whi... |
| CVE-2014-5203 | — | — | 3.9% | Aug 18, 2014 | wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remo... |
| CVE-2014-5043 | — | — | — | Aug 18, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-3799 | — | — | — | Aug 18, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-2388 | — | — | 1.2% | Aug 18, 2014 | The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforc... |
| CVE-2014-1470 | — | — | — | Aug 18, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2388. Reason: This candidate is a reservation ... |
| CVE-2014-1469 | — | — | 0.4% | Aug 18, 2014 | BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials du... |
| CVE-2014-5074 | — | — | 9.7% | Aug 17, 2014 | Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device... |
| CVE-2014-4775 | — | — | 1.2% | Aug 17, 2014 | IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSph... |
| CVE-2014-3087 | — | — | 1.3% | Aug 17, 2014 | callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.... |
| CVE-2014-3085 | — | — | 7.6% | Aug 17, 2014 | systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote auth... |
| CVE-2014-3081 | — | — | 4.1% | Aug 17, 2014 | prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote aut... |
| CVE-2014-3080 | — | — | 3.5% | Aug 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware... |
| CVE-2014-3063 | — | — | 1.2% | Aug 17, 2014 | IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSph... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now