2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5185 | — | — | 1.9% | Aug 6, 2014 | SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor... |
| CVE-2014-5184 | — | — | 1.6% | Aug 6, 2014 | SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote a... |
| CVE-2014-5183 | — | — | 1.6% | Aug 6, 2014 | SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1... |
| CVE-2014-5182 | — | — | 2.3% | Aug 6, 2014 | Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contr... |
| CVE-2014-5181 | — | — | 4.3% | Aug 6, 2014 | Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress... |
| CVE-2014-5180 | — | — | 2.4% | Aug 6, 2014 | SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 fo... |
| CVE-2014-3559 | — | — | 1.4% | Aug 6, 2014 | The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, ev... |
| CVE-2014-3434 | — | — | 1.6% | Aug 6, 2014 | Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, ... |
| CVE-2014-0479 | — | — | 2.7% | Aug 6, 2014 | reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vect... |
| CVE-2014-5179 | — | — | 1.2% | Aug 6, 2014 | The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access pe... |
| CVE-2014-5178 | — | — | 1.8% | Aug 6, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated... |
| CVE-2014-5090 | — | — | 2.8% | Aug 6, 2014 | admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell me... |
| CVE-2014-5089 | — | — | 1.2% | Aug 6, 2014 | SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute ... |
| CVE-2014-5088 | — | — | 1.5% | Aug 6, 2014 | Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via ... |
| CVE-2014-5082 | — | — | 2.1% | Aug 6, 2014 | Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus al... |
| CVE-2014-3560 | — | — | 56.4% | Aug 6, 2014 | NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to exec... |
| CVE-2014-5177 | — | — | 0.5% | Aug 3, 2014 | libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitr... |
| CVE-2014-0179 | — | — | 0.6% | Aug 3, 2014 | libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a cra... |
| CVE-2014-5165 | — | — | 2.8% | Aug 1, 2014 | The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1... |
| CVE-2014-5164 | — | — | 2.8% | Aug 1, 2014 | The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initia... |
| CVE-2014-5163 | — | — | 3.3% | Aug 1, 2014 | The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP an... |
| CVE-2014-5162 | — | — | 2.5% | Aug 1, 2014 | The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.... |
| CVE-2014-5161 | — | — | 2.5% | Aug 1, 2014 | The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not ... |
| CVE-2014-5160 | — | — | 34.8% | Aug 1, 2014 | Multiple directory traversal vulnerabilities in crs.exe in the Cell Request Service in HP Data Protector allow remote at... |
| CVE-2014-5077 | — | — | 5.8% | Aug 1, 2014 | The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is e... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now