2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3290 | — | — | 1.1% | Jun 14, 2014 | The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote ... |
| CVE-2014-2176 | — | — | 2.8% | Jun 14, 2014 | Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to... |
| CVE-2014-2002 | — | — | 0.9% | Jun 14, 2014 | Cross-site scripting (XSS) vulnerability in C-BOARD Moyuku 1.01b6 and earlier allows remote attackers to inject arbitrar... |
| CVE-2014-0960 | — | — | 0.6% | Jun 14, 2014 | IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypa... |
| CVE-2014-0186 | — | — | 2.4% | Jun 14, 2014 | A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL) 7 allows remote attackers to cause a de... |
| CVE-2014-3295 | — | — | 1.1% | Jun 14, 2014 | The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a ... |
| CVE-2014-4161 | — | — | 1.2% | Jun 13, 2014 | Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote... |
| CVE-2014-4160 | — | — | 1.2% | Jun 13, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas node in SAP NetWeaver Business Client (NWBC) allow... |
| CVE-2014-4159 | — | — | 1.3% | Jun 13, 2014 | Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attacker... |
| CVE-2014-4158 | — | — | 14.3% | Jun 13, 2014 | Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req... |
| CVE-2014-3814 | — | — | 1.3% | Jun 13, 2014 | The Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS loo... |
| CVE-2014-3813 | — | — | 1.3% | Jun 13, 2014 | Unspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configur... |
| CVE-2014-3812 | — | — | 0.7% | Jun 13, 2014 | The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos ... |
| CVE-2014-3805 | — | — | 13.1% | Jun 13, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a... |
| CVE-2014-3804 | — | — | 73.0% | Jun 13, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a... |
| CVE-2014-2303 | — | — | 2.6% | Jun 13, 2014 | Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and... |
| CVE-2014-3859 | — | — | 7.0% | Jun 13, 2014 | libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a deni... |
| CVE-2014-4037 | — | — | 2.9% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php ... |
| CVE-2014-4036 | — | — | 1.0% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to in... |
| CVE-2014-4035 | — | — | 3.3% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0... |
| CVE-2014-4034 | — | — | 6.3% | Jun 11, 2014 | SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com... |
| CVE-2014-4033 | — | — | 3.3% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows ... |
| CVE-2014-4032 | — | — | 1.9% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in apps/app_comment/form_comment.php in Fiyo CMS 1.5.7 allows remote attackers ... |
| CVE-2014-3980 | — | — | 0.4% | Jun 11, 2014 | libfep 0.0.5 before 0.1.0 does not properly use UNIX domain sockets in the abstract namespace, which allows local users ... |
| CVE-2014-3970 | — | — | 1.5% | Jun 11, 2014 | The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now