2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3041 | — | — | 1.0% | Aug 26, 2014 | SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 i... |
| CVE-2014-3035 | — | — | 0.9% | Aug 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, ... |
| CVE-2014-3034 | — | — | 0.9% | Aug 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x befo... |
| CVE-2014-2528 | — | — | 2.9% | Aug 26, 2014 | kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers ... |
| CVE-2014-2527 | — | — | 3.0% | Aug 26, 2014 | kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers ... |
| CVE-2014-0483 | — | — | 2.0% | Aug 26, 2014 | The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 be... |
| CVE-2014-0482 | — | — | 2.0% | Aug 26, 2014 | The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.... |
| CVE-2014-0481 | — | — | 2.5% | Aug 26, 2014 | The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before ... |
| CVE-2014-0480 | — | — | 2.3% | Aug 26, 2014 | The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before r... |
| CVE-2014-4790 | — | — | 0.8% | Aug 26, 2014 | IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x b... |
| CVE-2014-3335 | — | — | 1.1% | Aug 26, 2014 | Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicas... |
| CVE-2014-3040 | — | — | 0.9% | Aug 26, 2014 | Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0... |
| CVE-2014-3033 | — | — | 0.9% | Aug 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0... |
| CVE-2014-5458 | — | — | 1.3% | Aug 25, 2014 | SQL injection vulnerability in sqrl_verify.php in php-sqrl allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2014-5457 | — | — | 0.3% | Aug 25, 2014 | QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /... |
| CVE-2014-5456 | — | — | 0.9% | Aug 25, 2014 | Cross-site scripting (XSS) vulnerability in the Social Stats module before 7.x-1.5 for Drupal allows remote authenticate... |
| CVE-2014-5455 | MEDIUM | 5.3 | 1.0% | Aug 25, 2014 | Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and Ope... |
| CVE-2014-5454 | — | — | 2.4% | Aug 25, 2014 | Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authentica... |
| CVE-2014-5453 | — | — | 1.0% | Aug 25, 2014 | Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory ... |
| CVE-2014-5335 | — | — | 1.2% | Aug 25, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attack... |
| CVE-2014-5356 | — | — | 2.1% | Aug 25, 2014 | OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, ... |
| CVE-2014-5253 | — | — | 1.5% | Aug 25, 2014 | OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a d... |
| CVE-2014-5252 | — | — | 1.5% | Aug 25, 2014 | The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at valu... |
| CVE-2014-5251 | — | — | 1.6% | Aug 25, 2014 | The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timesta... |
| CVE-2014-3589 | — | — | 3.6% | Aug 25, 2014 | PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote atta... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now