2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0969 | — | — | 0.7% | Aug 17, 2014 | Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collabor... |
| CVE-2014-0966 | — | — | 1.0% | Aug 17, 2014 | SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x a... |
| CVE-2014-0905 | — | — | 0.5% | Aug 17, 2014 | IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which... |
| CVE-2014-0876 | — | — | 0.4% | Aug 17, 2014 | Buffer overflow in the Java GUI Configuration Wizard and Preferences Editor in the backup-archive client in IBM Tivoli S... |
| CVE-2014-0327 | — | — | 3.7% | Aug 17, 2014 | The Terminal Upgrade Tool in the Pilot Below Deck Equipment (BDE) and OpenPort implementations on Iridium satellite term... |
| CVE-2014-0326 | — | — | 2.2% | Aug 17, 2014 | The Pilot Below Deck Equipment (BDE) and OpenPort implementations on Iridium satellite terminals allow remote attackers ... |
| CVE-2014-3905 | — | — | 0.9% | Aug 17, 2014 | Cross-site scripting (XSS) vulnerability in tenfourzero Shutter 0.1.4 allows remote attackers to inject arbitrary web sc... |
| CVE-2014-3904 | — | — | 1.2% | Aug 17, 2014 | SQL injection vulnerability in lib/admin.php in tenfourzero Shutter 0.1.4 allows remote attackers to execute arbitrary S... |
| CVE-2014-3900 | — | — | 1.8% | Aug 17, 2014 | Cross-site scripting (XSS) vulnerability in admin/picture_modify.php in the photo-edit subsystem in Piwigo 2.6.3 and ear... |
| CVE-2014-0609 | — | — | 2.2% | Aug 17, 2014 | Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 ... |
| CVE-2014-5260 | — | — | 0.3% | Aug 16, 2014 | The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a sy... |
| CVE-2014-0852 | — | — | 1.2% | Aug 16, 2014 | IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x thro... |
| CVE-2014-3902 | — | — | 0.8% | Aug 15, 2014 | The CyberAgent Ameba application 3.x and 4.x before 4.5.0 for Android does not verify X.509 certificates from SSL server... |
| CVE-2014-2964 | — | — | 0.5% | Aug 15, 2014 | Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4... |
| CVE-2014-2943 | — | — | — | Aug 15, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2886, CVE-2014-2942. Reason: this ID was inten... |
| CVE-2014-2941 | — | — | 2.0% | Aug 15, 2014 | Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access... |
| CVE-2014-2940 | — | — | 2.2% | Aug 15, 2014 | Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the a... |
| CVE-2014-0328 | — | — | 2.8% | Aug 15, 2014 | The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to ... |
| CVE-2014-5250 | — | — | 2.4% | Aug 14, 2014 | Unspecified vulnerability in the AJAX autocompletion callback in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 a... |
| CVE-2014-5249 | — | — | 1.9% | Aug 14, 2014 | SQL injection vulnerability in the "Biblio self autocomplete" submodule in the Biblio Autocomplete module 6.x-1.x before... |
| CVE-2014-5248 | — | — | 0.9% | Aug 14, 2014 | Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or... |
| CVE-2014-1546 | — | — | 0.5% | Aug 14, 2014 | The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x befor... |
| CVE-2014-1390 | — | — | 2.4% | Aug 14, 2014 | WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1389 | — | — | 2.8% | Aug 14, 2014 | WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1388 | — | — | 2.8% | Aug 14, 2014 | WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now