2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4857 | — | — | 1.7% | Jul 26, 2014 | Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web... |
| CVE-2014-4748 | — | — | 2.0% | Jul 26, 2014 | Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote... |
| CVE-2014-4747 | — | — | 0.6% | Jul 26, 2014 | The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeti... |
| CVE-2014-2966 | — | — | 1.7% | Jul 26, 2014 | The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote... |
| CVE-2014-2626 | — | — | 19.4% | Jul 26, 2014 | Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Vi... |
| CVE-2014-2625 | — | — | 9.9% | Jul 26, 2014 | Directory traversal vulnerability in the storedNtxFile function in HP Network Virtualization 8.6 (aka Shunra Network Vir... |
| CVE-2014-4979 | — | — | 3.6% | Jul 26, 2014 | Apple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a... |
| CVE-2014-4858 | — | — | 1.3% | Jul 26, 2014 | Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier all... |
| CVE-2014-3328 | — | — | 3.0% | Jul 26, 2014 | The Intercluster Sync Agent Service in Cisco Unified Presence Server allows remote attackers to cause a denial of servic... |
| CVE-2014-3326 | — | — | 2.1% | Jul 26, 2014 | SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users... |
| CVE-2014-3324 | — | — | 1.5% | Jul 26, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TeleP... |
| CVE-2014-3305 | — | — | 1.3% | Jul 26, 2014 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earl... |
| CVE-2014-3301 | — | — | 1.8% | Jul 26, 2014 | The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to ob... |
| CVE-2014-3071 | — | — | 1.2% | Jul 26, 2014 | Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows re... |
| CVE-2014-2363 | — | — | 2.1% | Jul 26, 2014 | Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain ac... |
| CVE-2014-5103 | — | — | 3.5% | Jul 25, 2014 | Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to ... |
| CVE-2014-5102 | — | — | 1.4% | Jul 25, 2014 | SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL co... |
| CVE-2014-5101 | — | — | 2.5% | Jul 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script... |
| CVE-2014-5100 | — | — | 2.5% | Jul 25, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au... |
| CVE-2014-5027 | — | — | 1.3% | Jul 25, 2014 | Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attack... |
| CVE-2014-2227 | — | — | 2.2% | Jul 25, 2014 | The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVisi... |
| CVE-2014-5024 | — | — | 1.6% | Jul 24, 2014 | Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 al... |
| CVE-2014-5015 | — | — | 1.7% | Jul 24, 2014 | bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrict... |
| CVE-2014-4927 | — | — | 11.2% | Jul 24, 2014 | Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 router... |
| CVE-2014-4910 | — | — | 1.0% | Jul 24, 2014 | Directory traversal vulnerability in tools/backlight_helper.c in X.Org xf86-video-intel 2.99.911 allows remote attackers... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now