2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2216 | — | — | 5.1% | Aug 25, 2014 | The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows r... |
| CVE-2014-4325 | — | — | 0.4% | Aug 25, 2014 | The cmd_boot function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation... |
| CVE-2014-0974 | — | — | 0.3% | Aug 25, 2014 | The boot_linux_from_mmc function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm... |
| CVE-2014-0973 | — | — | 0.4% | Aug 25, 2014 | The image_verify function in platform/msm_shared/image_verify.c in the Little Kernel (LK) bootloader, as distributed wit... |
| CVE-2014-2634 | — | — | 6.4% | Aug 23, 2014 | Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to b... |
| CVE-2014-2633 | — | — | 1.8% | Aug 23, 2014 | Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows... |
| CVE-2014-2632 | — | — | 13.3% | Aug 23, 2014 | Unspecified vulnerability in the WebTier component in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote att... |
| CVE-2014-5120 | — | — | 16.9% | Aug 23, 2014 | gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 ... |
| CVE-2014-3597 | — | — | 15.4% | Aug 23, 2014 | Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16... |
| CVE-2014-3587 | — | — | 20.2% | Aug 23, 2014 | Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component... |
| CVE-2014-5243 | — | — | 1.8% | Aug 22, 2014 | MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME prote... |
| CVE-2014-5242 | — | — | 2.1% | Aug 22, 2014 | Cross-site scripting (XSS) vulnerability in mediawiki.page.image.pagination.js in MediaWiki 1.22.x before 1.22.9 and 1.2... |
| CVE-2014-5241 | — | — | 0.8% | Aug 22, 2014 | The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, a... |
| CVE-2014-3563 | — | — | 0.4% | Aug 22, 2014 | Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified i... |
| CVE-2014-5396 | — | — | 2.1% | Aug 22, 2014 | The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for t... |
| CVE-2014-5368 | — | — | 18.8% | Aug 22, 2014 | Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Sour... |
| CVE-2014-5338 | — | — | 1.7% | Aug 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 befo... |
| CVE-2014-5262 | — | — | 2.3% | Aug 22, 2014 | SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote ... |
| CVE-2014-5261 | — | — | 10.8% | Aug 22, 2014 | The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary ... |
| CVE-2014-5246 | — | — | 12.5% | Aug 22, 2014 | The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication... |
| CVE-2014-5149 | — | — | 0.4% | Aug 22, 2014 | Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, whi... |
| CVE-2014-5146 | — | — | 0.4% | Aug 22, 2014 | Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assiste... |
| CVE-2014-5122 | — | — | 2.1% | Aug 22, 2014 | Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web ... |
| CVE-2014-5121 | — | — | 2.4% | Aug 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject ar... |
| CVE-2014-5097 | — | — | 2.3% | Aug 22, 2014 | Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execut... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now