2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4948 | — | — | 1.9% | Jul 22, 2014 | Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of servi... |
| CVE-2014-4947 | — | — | 5.4% | Jul 22, 2014 | Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified i... |
| CVE-2014-3530 | — | — | 3.9% | Jul 22, 2014 | The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Ent... |
| CVE-2014-3518 | — | — | 2.6% | Jul 22, 2014 | jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss... |
| CVE-2014-5023 | — | — | 3.4% | Jul 22, 2014 | Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary comman... |
| CVE-2014-5022 | — | — | 1.0% | Jul 22, 2014 | Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject ... |
| CVE-2014-5021 | — | — | 1.1% | Jul 22, 2014 | Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows r... |
| CVE-2014-5020 | — | — | 1.3% | Jul 22, 2014 | The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authent... |
| CVE-2014-5019 | — | — | 2.8% | Jul 22, 2014 | The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service... |
| CVE-2014-4911 | — | — | 2.4% | Jul 22, 2014 | The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attacke... |
| CVE-2014-4511 | — | — | 82.7% | Jul 22, 2014 | Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in ... |
| CVE-2014-4326 | — | — | 3.3% | Jul 22, 2014 | Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a cra... |
| CVE-2014-2385 | — | — | 4.5% | Jul 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow loca... |
| CVE-2014-5018 | — | — | 1.5% | Jul 21, 2014 | Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allo... |
| CVE-2014-5017 | — | — | 1.9% | Jul 21, 2014 | SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 14... |
| CVE-2014-5016 | — | — | 1.5% | Jul 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject ar... |
| CVE-2014-4960 | — | — | 2.3% | Jul 21, 2014 | Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x throu... |
| CVE-2014-4734 | — | — | 1.9% | Jul 21, 2014 | Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to ... |
| CVE-2014-4987 | — | — | 1.3% | Jul 20, 2014 | server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to b... |
| CVE-2014-4986 | — | — | 1.6% | Jul 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before... |
| CVE-2014-4955 | — | — | 1.5% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpM... |
| CVE-2014-4954 | — | — | 1.5% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in php... |
| CVE-2014-4342 | — | — | 6.5% | Jul 20, 2014 | MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffe... |
| CVE-2014-4341 | — | — | 7.1% | Jul 20, 2014 | MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and appli... |
| CVE-2014-3894 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in PHP Kobo Multifunctional MailForm Free 2014/1/28 and earlier allows remote a... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now