2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4850 | — | — | 1.3% | Jul 10, 2014 | SQL injection vulnerability in index.php in FoeCMS allows remote attackers to execute arbitrary SQL commands via the i p... |
| CVE-2014-4849 | — | — | 1.0% | Jul 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web ... |
| CVE-2014-4848 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Blogstand Banner (blogstand-smart-banner) plugin 1.0 for WordPress allow... |
| CVE-2014-4847 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Random Banner plugin 1.1.2.1 for WordPress allows remote attackers to in... |
| CVE-2014-4846 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers... |
| CVE-2014-4845 | — | — | 1.6% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in the BannerMan plugin 0.2.4 for WordPress allows remote attackers to inject a... |
| CVE-2014-4698 | — | — | 0.7% | Jul 10, 2014 | Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent ... |
| CVE-2014-4670 | — | — | 0.7% | Jul 10, 2014 | Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent... |
| CVE-2014-3888 | — | — | 62.3% | Jul 10, 2014 | Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V... |
| CVE-2014-3318 | — | — | 3.0% | Jul 10, 2014 | Directory traversal vulnerability in dna/viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unif... |
| CVE-2014-3316 | — | — | 1.8% | Jul 10, 2014 | The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remot... |
| CVE-2014-3315 | — | — | 1.2% | Jul 10, 2014 | Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco U... |
| CVE-2014-3311 | — | — | 3.4% | Jul 10, 2014 | Heap-based buffer overflow in the file-sharing feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx... |
| CVE-2014-3310 | — | — | 1.2% | Jul 10, 2014 | The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not veri... |
| CVE-2014-2963 | — | — | 1.7% | Jul 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X ... |
| CVE-2014-4744 | — | — | 1.9% | Jul 9, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary ... |
| CVE-2014-4743 | — | — | 1.9% | Jul 9, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in (1) search_ajax.tpl and (2) search_ajax_small.tpl in templates/de... |
| CVE-2014-4742 | — | — | 1.9% | Jul 9, 2014 | Cross-site scripting (XSS) vulnerability in system/class_link.php in the System module (module_system) in Kajona before ... |
| CVE-2014-4741 | — | — | 2.1% | Jul 9, 2014 | SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQ... |
| CVE-2014-4740 | — | — | — | Jul 9, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-4907, CVE-2014-4908. Reason: This candidate is... |
| CVE-2014-4194 | — | — | 1.2% | Jul 9, 2014 | SQL injection vulnerability in zero_transact_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL... |
| CVE-2014-4022 | — | — | 0.5% | Jul 9, 2014 | The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly i... |
| CVE-2014-4699 | — | — | 2.3% | Jul 9, 2014 | The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved... |
| CVE-2014-3891 | — | — | 2.0% | Jul 9, 2014 | Buffer overflow in RimArts Becky! Internet Mail before 2.68 allows remote POP3 servers to execute arbitrary code via a c... |
| CVE-2014-3515 | — | — | 30.1% | Jul 9, 2014 | The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now