2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1820 | — | — | 14.7% | Aug 12, 2014 | Cross-site scripting (XSS) vulnerability in Master Data Services (MDS) in Microsoft SQL Server 2012 SP1 and 2014 on 64-b... |
| CVE-2014-1819 | — | — | 2.0% | Aug 12, 2014 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a... |
| CVE-2014-1814 | — | — | 2.0% | Aug 12, 2014 | The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windo... |
| CVE-2014-0546 | CRITICAL | 9.8 | 22.3% | Aug 12, 2014 | Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox prot... |
| CVE-2014-0318 | — | — | 1.8% | Aug 12, 2014 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a... |
| CVE-2014-0316 | — | — | 11.5% | Aug 12, 2014 | Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Window... |
| CVE-2014-5201 | — | — | 4.6% | Aug 12, 2014 | SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary... |
| CVE-2014-5200 | — | — | 4.4% | Aug 12, 2014 | SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute a... |
| CVE-2014-5199 | — | — | 1.0% | Aug 12, 2014 | Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for Wo... |
| CVE-2014-5198 | — | — | 1.8% | Aug 12, 2014 | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers t... |
| CVE-2014-5197 | — | — | 2.2% | Aug 12, 2014 | Directory traversal vulnerability in (1) Splunk Web or the (2) Splunkd HTTP Server in Splunk Enterprise 6.1.x before 6.1... |
| CVE-2014-5196 | — | — | 2.1% | Aug 12, 2014 | Cross-site request forgery (CSRF) vulnerability in improved-user-search-in-backend.php in the backend in the Improved us... |
| CVE-2014-3072 | — | — | 0.4% | Aug 12, 2014 | Unspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1... |
| CVE-2014-2629 | — | — | 2.1% | Aug 12, 2014 | HP NonStop Safeguard Security Software G, H06.03 through H06.28.01, and J06.03 through J06.17.01 does not properly evalu... |
| CVE-2014-4760 | — | — | 1.8% | Aug 12, 2014 | Open redirect vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 th... |
| CVE-2014-4751 | — | — | 1.8% | Aug 12, 2014 | Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Mobile 8.0.0.0, 8.0.0.1, and 8.0.0.3 allows ... |
| CVE-2014-4746 | — | — | 2.1% | Aug 12, 2014 | IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traver... |
| CVE-2014-3899 | — | — | 1.5% | Aug 12, 2014 | Gretech GOM Player 2.2.51.5149 and earlier allows remote attackers to cause a denial of service (launch outage) via a cr... |
| CVE-2014-3102 | — | — | 1.4% | Aug 12, 2014 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF1... |
| CVE-2014-2630 | — | — | 7.1% | Aug 12, 2014 | Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u... |
| CVE-2014-0953 | — | — | 1.8% | Aug 12, 2014 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 C... |
| CVE-2014-4757 | — | — | 0.3% | Aug 12, 2014 | The Outlook Extension in IBM Content Collector 4.0.0.x before 4.0.0.0-ICC-OE-IF004 allows local users to bypass the inte... |
| CVE-2014-3086 | — | — | 5.1% | Aug 12, 2014 | Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7... |
| CVE-2014-3069 | — | — | 1.0% | Aug 12, 2014 | Multiple CRLF injection vulnerabilities in the Universal Access component in IBM Curam Social Program Management (SPM) 6... |
| CVE-2014-3031 | — | — | 0.8% | Aug 12, 2014 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 befo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now