2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4505 | — | — | 1.2% | Jun 20, 2014 | Cross-site scripting (XSS) vulnerability in the Easy Breadcrumb module 7.x-2.x before 7.x-2.10 for Drupal allows remote ... |
| CVE-2014-3496 | — | — | 5.0% | Jun 20, 2014 | cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitr... |
| CVE-2014-0007 | — | — | 9.0% | Jun 20, 2014 | The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via... |
| CVE-2014-4335 | — | — | 1.4% | Jun 19, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive 6.7.2 allow remote attackers to inject arbitrary w... |
| CVE-2014-4334 | — | — | 15.2% | Jun 19, 2014 | Stack-based buffer overflow in Ubisoft Rayman Legends before 1.3.140380 allows remote attackers to execute arbitrary cod... |
| CVE-2014-4333 | — | — | 0.9% | Jun 19, 2014 | Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remot... |
| CVE-2014-4155 | — | — | 2.3% | Jun 19, 2014 | Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows rem... |
| CVE-2014-3810 | — | — | 1.7% | Jun 19, 2014 | SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticat... |
| CVE-2014-3778 | — | — | 1.9% | Jun 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboar... |
| CVE-2014-4329 | — | — | 1.2% | Jun 19, 2014 | Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitra... |
| CVE-2014-2962 | — | — | 47.1% | Jun 19, 2014 | Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware befor... |
| CVE-2014-2782 | — | — | 22.4% | Jun 19, 2014 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ... |
| CVE-2014-2611 | — | — | 11.9% | Jun 19, 2014 | Directory traversal vulnerability in the fndwar web application in HP Executive Scorecard 9.40 and 9.41 allows remote au... |
| CVE-2014-2610 | — | — | 5.3% | Jun 19, 2014 | Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 ... |
| CVE-2014-2609 | — | — | 12.9% | Jun 19, 2014 | The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows r... |
| CVE-2014-2001 | — | — | 0.6% | Jun 19, 2014 | The East Japan Railway Company JR East Japan application before 1.2.0 for Android does not verify X.509 certificates fro... |
| CVE-2014-4286 | — | — | — | Jun 18, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4286. Reason: This candidate is a duplicate of... |
| CVE-2014-4153 | — | — | 7.4% | Jun 18, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a craft... |
| CVE-2014-4152 | — | — | 5.8% | Jun 18, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a cra... |
| CVE-2014-4151 | — | — | 7.3% | Jun 18, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execu... |
| CVE-2014-4049 | — | — | 10.9% | Jun 18, 2014 | Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote... |
| CVE-2014-4021 | — | — | 0.7% | Jun 18, 2014 | Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to... |
| CVE-2014-1652 | — | — | 1.7% | Jun 18, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 a... |
| CVE-2014-1651 | — | — | 2.0% | Jun 18, 2014 | SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allow... |
| CVE-2014-1650 | — | — | 1.4% | Jun 18, 2014 | SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now