2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5103 | — | — | 3.5% | Jul 25, 2014 | Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to ... |
| CVE-2014-5102 | — | — | 1.4% | Jul 25, 2014 | SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL co... |
| CVE-2014-5101 | — | — | 2.5% | Jul 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script... |
| CVE-2014-5100 | — | — | 2.5% | Jul 25, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au... |
| CVE-2014-5027 | — | — | 1.3% | Jul 25, 2014 | Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attack... |
| CVE-2014-2227 | — | — | 2.2% | Jul 25, 2014 | The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVisi... |
| CVE-2014-5024 | — | — | 1.6% | Jul 24, 2014 | Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 al... |
| CVE-2014-5015 | — | — | 1.7% | Jul 24, 2014 | bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrict... |
| CVE-2014-4927 | — | — | 11.2% | Jul 24, 2014 | Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 router... |
| CVE-2014-4910 | — | — | 1.0% | Jul 24, 2014 | Directory traversal vulnerability in tools/backlight_helper.c in X.Org xf86-video-intel 2.99.911 allows remote attackers... |
| CVE-2014-4736 | — | — | 2.3% | Jul 24, 2014 | SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the no... |
| CVE-2014-4686 | — | — | 1.1% | Jul 24, 2014 | The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a ha... |
| CVE-2014-4685 | — | — | 0.4% | Jul 24, 2014 | Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveragin... |
| CVE-2014-4684 | — | — | 1.3% | Jul 24, 2014 | The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated... |
| CVE-2014-4683 | — | — | 1.2% | Jul 24, 2014 | The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authentic... |
| CVE-2014-4682 | — | — | 1.7% | Jul 24, 2014 | The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers... |
| CVE-2014-3322 | — | — | 1.2% | Jul 24, 2014 | Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which all... |
| CVE-2014-3110 | — | — | 5.3% | Jul 24, 2014 | Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli... |
| CVE-2014-2971 | — | — | 0.9% | Jul 24, 2014 | Cross-site scripting (XSS) vulnerability in AddStdLetter.jsp in MicroPact iComplaints before 8.0.2.1.8.8014 allows remot... |
| CVE-2014-2968 | — | — | 0.8% | Jul 24, 2014 | Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37... |
| CVE-2014-2717 | — | — | 3.7% | Jul 24, 2014 | Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11... |
| CVE-2014-2370 | — | — | 1.4% | Jul 24, 2014 | Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.... |
| CVE-2014-2369 | — | — | 0.6% | Jul 24, 2014 | Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI termi... |
| CVE-2014-2362 | — | — | 1.6% | Jul 24, 2014 | OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key g... |
| CVE-2014-2361 | — | — | 0.4% | Jul 24, 2014 | OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication fo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now