2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2956 | — | — | 4.2% | Jul 8, 2014 | ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.5... |
| CVE-2014-2514 | — | — | 2.9% | Jul 8, 2014 | EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not proper... |
| CVE-2014-2513 | — | — | 2.9% | Jul 8, 2014 | EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not proper... |
| CVE-2014-2510 | — | — | 2.1% | Jul 8, 2014 | The JAXB XML parser in EMC Documentum Foundation Services (DFS) 6.6 before P39, 6.7 SP1 before P28, and 6.7 SP2 before P... |
| CVE-2014-3540 | — | — | — | Jul 8, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0114. Reason: This candidate is a duplicate of... |
| CVE-2014-4724 | — | — | 1.6% | Jul 7, 2014 | Cross-site scripting (XSS) vulnerability in the Custom Banners plugin 1.2.2.2 for WordPress allows remote attackers to i... |
| CVE-2014-4723 | — | — | 1.6% | Jul 7, 2014 | Cross-site scripting (XSS) vulnerability in the Easy Banners plugin 1.4 for WordPress allows remote attackers to inject ... |
| CVE-2014-4722 | — | — | 2.3% | Jul 7, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the OCS Reports Web Interface in OCS Inventory NG allow remote at... |
| CVE-2014-4646 | — | — | 2.5% | Jul 7, 2014 | Buffer overflow in the FPDFBookmark_GetTitle method in Foxit PDF SDK DLL before 3.1.1.5005 allows context-dependent atta... |
| CVE-2014-3489 | — | — | 1.6% | Jul 7, 2014 | lib/util/miq-password.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 uses a hard-coded salt, which... |
| CVE-2014-3486 | — | — | 0.4% | Jul 7, 2014 | The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Re... |
| CVE-2014-3481 | — | — | 3.0% | Jul 7, 2014 | org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6... |
| CVE-2014-0248 | — | — | 3.5% | Jul 7, 2014 | org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform ... |
| CVE-2014-0184 | — | — | 0.4% | Jul 7, 2014 | Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 logs the root password when deploying a VM, which allows ... |
| CVE-2014-0180 | — | — | 1.8% | Jul 7, 2014 | The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFM... |
| CVE-2014-0176 | — | — | 1.4% | Jul 7, 2014 | Cross-site scripting (XSS) vulnerability in application/panel_control in CloudForms 3.0 Management Engine (CFME) before ... |
| CVE-2014-0035 | — | — | 7.1% | Jul 7, 2014 | The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the U... |
| CVE-2014-0034 | — | — | 7.4% | Jul 7, 2014 | The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens... |
| CVE-2014-3483 | — | — | 4.2% | Jul 7, 2014 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQ... |
| CVE-2014-3482 | — | — | 4.9% | Jul 7, 2014 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQ... |
| CVE-2014-3308 | — | — | 2.8% | Jul 7, 2014 | Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cau... |
| CVE-2014-3300 | — | — | 21.9% | Jul 7, 2014 | The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application ... |
| CVE-2014-3113 | — | — | 5.2% | Jul 7, 2014 | Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code v... |
| CVE-2014-2969 | — | — | 1.5% | Jul 7, 2014 | NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser ... |
| CVE-2014-2967 | — | — | 5.1% | Jul 7, 2014 | Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library c... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now