2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2524 | — | — | 0.4% | Aug 20, 2014 | The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary... |
| CVE-2014-4750 | — | — | 0.6% | Aug 20, 2014 | IBM PowerVC Express Edition 1.2.0 before FixPack3 establishes an FTP session for transferring files to a managed IVM, wh... |
| CVE-2014-4749 | — | — | 0.9% | Aug 20, 2014 | IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers t... |
| CVE-2014-4618 | — | — | 2.4% | Aug 20, 2014 | EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to gain privil... |
| CVE-2014-3514 | — | — | 2.8% | Aug 20, 2014 | activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x ... |
| CVE-2014-3340 | — | — | 2.3% | Aug 20, 2014 | Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote auth... |
| CVE-2014-3331 | — | — | 1.7% | Aug 20, 2014 | The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.... |
| CVE-2014-2521 | — | — | 1.7% | Aug 20, 2014 | EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to read sensit... |
| CVE-2014-2520 | — | — | 1.7% | Aug 20, 2014 | EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly... |
| CVE-2014-2518 | — | — | 1.0% | Aug 20, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15... |
| CVE-2014-2517 | — | — | 1.2% | Aug 20, 2014 | Unspecified vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to gain pr... |
| CVE-2014-2515 | — | — | 2.4% | Aug 20, 2014 | EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properl... |
| CVE-2014-2511 | — | — | 1.8% | Aug 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 a... |
| CVE-2014-2505 | — | — | 0.7% | Aug 20, 2014 | EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to trigger the download of arbitrary code, and co... |
| CVE-2014-0641 | — | — | 0.6% | Aug 20, 2014 | Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attacker... |
| CVE-2014-0640 | — | — | 1.2% | Aug 20, 2014 | EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to bypass intended restrictions on reso... |
| CVE-2014-5350 | — | — | 63.9% | Aug 19, 2014 | Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read... |
| CVE-2014-5349 | — | — | 3.8% | Aug 19, 2014 | Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (... |
| CVE-2014-5348 | — | — | 1.4% | Aug 19, 2014 | Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager V... |
| CVE-2014-5347 | — | — | 4.9% | Aug 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress... |
| CVE-2014-5346 | — | — | 2.7% | Aug 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow ... |
| CVE-2014-5345 | — | — | 6.1% | Aug 19, 2014 | Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress al... |
| CVE-2014-5344 | — | — | 1.6% | Aug 19, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Mobiloud (mobiloud-mobile-app-plugin) plugin before 2.3.8 for... |
| CVE-2014-5343 | — | — | 1.9% | Aug 19, 2014 | Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML v... |
| CVE-2014-5033 | — | — | 0.4% | Aug 19, 2014 | KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, whic... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now