2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5195 | — | — | 0.3% | Aug 7, 2014 | Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switchin... |
| CVE-2014-5194 | — | — | 4.2% | Aug 7, 2014 | Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbi... |
| CVE-2014-5193 | — | — | 1.8% | Aug 7, 2014 | Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary... |
| CVE-2014-5192 | — | — | 1.2% | Aug 7, 2014 | SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL command... |
| CVE-2014-5191 | — | — | 1.8% | Aug 7, 2014 | Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to injec... |
| CVE-2014-5190 | — | — | 2.0% | Aug 7, 2014 | Cross-site scripting (XSS) vulnerability in captcha-secureimage/test/index.php in the SI CAPTCHA Anti-Spam plugin 2.7.4 ... |
| CVE-2014-5189 | — | — | 4.6% | Aug 7, 2014 | SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers... |
| CVE-2014-5188 | — | — | 1.9% | Aug 7, 2014 | Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote attackers ... |
| CVE-2014-4647 | — | — | 2.7% | Aug 7, 2014 | Stack-based buffer overflow in the loadExtensionFactory method in the TSVisualization ActiveX control in Embarcadero ER/... |
| CVE-2014-3914 | — | — | 72.6% | Aug 7, 2014 | Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows ... |
| CVE-2014-3855 | — | — | 1.8% | Aug 7, 2014 | Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a .... |
| CVE-2014-3854 | — | — | 0.9% | Aug 7, 2014 | Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack ... |
| CVE-2014-3853 | — | — | 1.3% | Aug 7, 2014 | Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attack... |
| CVE-2014-3852 | — | — | 1.5% | Aug 7, 2014 | Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remo... |
| CVE-2014-3851 | — | — | 0.4% | Aug 7, 2014 | usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local ... |
| CVE-2014-3800 | — | — | 0.4% | Aug 7, 2014 | XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names ... |
| CVE-2014-3774 | — | — | 1.9% | Aug 7, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in items.php in TeamPass before 2.1.20 allow remote attackers to inj... |
| CVE-2014-3773 | — | — | 2.1% | Aug 7, 2014 | Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL command... |
| CVE-2014-3772 | — | — | 2.6% | Aug 7, 2014 | TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a di... |
| CVE-2014-3771 | — | — | 2.6% | Aug 7, 2014 | TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request... |
| CVE-2014-3517 | — | — | 1.9% | Aug 7, 2014 | api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, whe... |
| CVE-2014-3459 | — | — | 11.6% | Aug 7, 2014 | Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execu... |
| CVE-2014-3429 | — | — | 4.7% | Aug 7, 2014 | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote att... |
| CVE-2014-5187 | — | — | 4.7% | Aug 6, 2014 | Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read ... |
| CVE-2014-5186 | — | — | 1.6% | Aug 6, 2014 | SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenti... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now