2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4736 | — | — | 2.3% | Jul 24, 2014 | SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the no... |
| CVE-2014-4686 | — | — | 1.1% | Jul 24, 2014 | The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a ha... |
| CVE-2014-4685 | — | — | 0.4% | Jul 24, 2014 | Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveragin... |
| CVE-2014-4684 | — | — | 1.3% | Jul 24, 2014 | The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated... |
| CVE-2014-4683 | — | — | 1.2% | Jul 24, 2014 | The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authentic... |
| CVE-2014-4682 | — | — | 1.7% | Jul 24, 2014 | The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers... |
| CVE-2014-3322 | — | — | 1.2% | Jul 24, 2014 | Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which all... |
| CVE-2014-3110 | — | — | 5.3% | Jul 24, 2014 | Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli... |
| CVE-2014-2971 | — | — | 0.9% | Jul 24, 2014 | Cross-site scripting (XSS) vulnerability in AddStdLetter.jsp in MicroPact iComplaints before 8.0.2.1.8.8014 allows remot... |
| CVE-2014-2968 | — | — | 0.8% | Jul 24, 2014 | Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37... |
| CVE-2014-2717 | — | — | 3.7% | Jul 24, 2014 | Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11... |
| CVE-2014-2370 | — | — | 1.4% | Jul 24, 2014 | Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.... |
| CVE-2014-2369 | — | — | 0.6% | Jul 24, 2014 | Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI termi... |
| CVE-2014-2362 | — | — | 1.6% | Jul 24, 2014 | OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key g... |
| CVE-2014-2361 | — | — | 0.4% | Jul 24, 2014 | OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication fo... |
| CVE-2014-2360 | — | — | 3.4% | Jul 24, 2014 | OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via ... |
| CVE-2014-1419 | — | — | 0.3% | Jul 24, 2014 | Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain pri... |
| CVE-2014-0607 | — | — | 3.4% | Jul 24, 2014 | Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows rem... |
| CVE-2014-4980 | — | — | 1.7% | Jul 23, 2014 | The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to... |
| CVE-2014-4503 | — | — | 1.2% | Jul 23, 2014 | The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle att... |
| CVE-2014-4502 | — | — | 3.3% | Jul 23, 2014 | Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFG... |
| CVE-2014-4501 | — | — | 2.9% | Jul 23, 2014 | Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow rem... |
| CVE-2014-3939 | — | — | 6.0% | Jul 23, 2014 | Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via... |
| CVE-2014-3938 | — | — | 4.3% | Jul 23, 2014 | Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted l... |
| CVE-2014-3555 | — | — | 2.2% | Jul 23, 2014 | OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to c... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now