2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4615 | — | — | 2.8% | Aug 19, 2014 | The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x ... |
| CVE-2014-3528 | — | — | 7.5% | Aug 19, 2014 | Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authenticati... |
| CVE-2014-3522 | — | — | 5.6% | Aug 19, 2014 | The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handl... |
| CVE-2014-3504 | — | — | 3.1% | Aug 19, 2014 | The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 throu... |
| CVE-2014-3490 | — | — | 4.6% | Aug 19, 2014 | RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3... |
| CVE-2014-3472 | — | — | 1.7% | Aug 19, 2014 | The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterp... |
| CVE-2014-3464 | — | — | 1.1% | Aug 19, 2014 | The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2... |
| CVE-2014-5333 | — | — | 3.5% | Aug 19, 2014 | Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Ad... |
| CVE-2014-3906 | — | — | 1.2% | Aug 19, 2014 | SQL injection vulnerability in OSK Advance-Flow 4.41 and earlier and Advance-Flow Forms 4.41 and earlier allows remote a... |
| CVE-2014-3903 | — | — | 1.5% | Aug 19, 2014 | Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated ... |
| CVE-2014-3341 | — | — | 4.7% | Aug 19, 2014 | The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages ... |
| CVE-2014-5266 | — | — | 24.4% | Aug 18, 2014 | The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, doe... |
| CVE-2014-5265 | — | — | 3.1% | Aug 18, 2014 | The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, per... |
| CVE-2014-5240 | — | — | 2.2% | Aug 18, 2014 | Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabl... |
| CVE-2014-5207 | — | — | 0.9% | Aug 18, 2014 | fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOE... |
| CVE-2014-5206 | — | — | 0.4% | Aug 18, 2014 | The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit... |
| CVE-2014-5205 | — | — | 1.8% | Aug 18, 2014 | wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and ui... |
| CVE-2014-5204 | — | — | 1.8% | Aug 18, 2014 | wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on whi... |
| CVE-2014-5203 | — | — | 3.9% | Aug 18, 2014 | wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remo... |
| CVE-2014-5043 | — | — | — | Aug 18, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-3799 | — | — | — | Aug 18, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-2388 | — | — | 1.2% | Aug 18, 2014 | The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforc... |
| CVE-2014-1470 | — | — | — | Aug 18, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2388. Reason: This candidate is a reservation ... |
| CVE-2014-1469 | — | — | 0.4% | Aug 18, 2014 | BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials du... |
| CVE-2014-5074 | — | — | 9.7% | Aug 17, 2014 | Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now