2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4167 | — | — | 1.7% | Jul 11, 2014 | The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenti... |
| CVE-2014-3992 | — | — | 2.0% | Jul 11, 2014 | Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary S... |
| CVE-2014-3991 | — | — | 2.7% | Jul 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary... |
| CVE-2014-3503 | — | — | 6.0% | Jul 11, 2014 | Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attack... |
| CVE-2014-3499 | — | — | 0.4% | Jul 11, 2014 | Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to ga... |
| CVE-2014-3485 | — | — | 1.5% | Jul 11, 2014 | The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authe... |
| CVE-2014-0174 | — | — | 1.6% | Jul 11, 2014 | Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-C... |
| CVE-2014-4908 | — | — | 1.9% | Jul 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitr... |
| CVE-2014-4907 | — | — | 2.2% | Jul 11, 2014 | Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.2... |
| CVE-2014-4856 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remo... |
| CVE-2014-4855 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to in... |
| CVE-2014-4854 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the WP Construction Mode plugin 1.8 for WordPress allows remote attackers to... |
| CVE-2014-4853 | — | — | 1.9% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users ... |
| CVE-2014-4852 | — | — | 2.2% | Jul 10, 2014 | SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to ... |
| CVE-2014-4851 | — | — | 1.1% | Jul 10, 2014 | Open redirect vulnerability in msg.php in FoeCMS allows remote attackers to redirect users to arbitrary web sites and co... |
| CVE-2014-4850 | — | — | 1.3% | Jul 10, 2014 | SQL injection vulnerability in index.php in FoeCMS allows remote attackers to execute arbitrary SQL commands via the i p... |
| CVE-2014-4849 | — | — | 1.0% | Jul 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web ... |
| CVE-2014-4848 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Blogstand Banner (blogstand-smart-banner) plugin 1.0 for WordPress allow... |
| CVE-2014-4847 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Random Banner plugin 1.1.2.1 for WordPress allows remote attackers to in... |
| CVE-2014-4846 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers... |
| CVE-2014-4845 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the BannerMan plugin 0.2.4 for WordPress allows remote attackers to inject a... |
| CVE-2014-4698 | — | — | 0.7% | Jul 10, 2014 | Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent ... |
| CVE-2014-4670 | — | — | 0.7% | Jul 10, 2014 | Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent... |
| CVE-2014-3888 | — | — | 62.3% | Jul 10, 2014 | Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V... |
| CVE-2014-3318 | — | — | 3.0% | Jul 10, 2014 | Directory traversal vulnerability in dna/viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unif... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now