2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3780 | — | — | 2.6% | May 30, 2014 | Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to by... |
| CVE-2014-0202 | — | — | 0.4% | May 30, 2014 | The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh... |
| CVE-2014-3463 | — | — | — | May 30, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-3285 | — | — | 3.0% | May 29, 2014 | Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not prop... |
| CVE-2014-3283 | — | — | 2.2% | May 29, 2014 | Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Commun... |
| CVE-2014-3282 | — | — | 2.0% | May 29, 2014 | The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and ear... |
| CVE-2014-3279 | — | — | 2.3% | May 29, 2014 | The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and ear... |
| CVE-2014-3277 | — | — | 2.1% | May 29, 2014 | The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and ear... |
| CVE-2014-3417 | — | — | 1.1% | May 29, 2014 | uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to config... |
| CVE-2014-3416 | — | — | 1.1% | May 29, 2014 | uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manag... |
| CVE-2014-3415 | — | — | 1.9% | May 29, 2014 | SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL command... |
| CVE-2014-3414 | — | — | 1.9% | May 29, 2014 | Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authenti... |
| CVE-2014-0246 | — | — | 1.3% | May 29, 2014 | SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitiv... |
| CVE-2014-0201 | — | — | 0.4% | May 29, 2014 | ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, use... |
| CVE-2014-0200 | — | — | 0.4% | May 29, 2014 | The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permiss... |
| CVE-2014-0199 | — | — | 0.4% | May 29, 2014 | The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) packa... |
| CVE-2014-0239 | — | — | 67.6% | May 28, 2014 | The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS ... |
| CVE-2014-0178 | — | — | 4.5% | May 28, 2014 | Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is... |
| CVE-2014-0240 | — | — | 0.4% | May 27, 2014 | The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by... |
| CVE-2014-0177 | — | — | 0.4% | May 27, 2014 | The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlin... |
| CVE-2014-3872 | — | — | 1.4% | May 27, 2014 | Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 ... |
| CVE-2014-3871 | — | — | 2.6% | May 27, 2014 | Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds ... |
| CVE-2014-3870 | — | — | 1.6% | May 27, 2014 | Cross-site scripting (XSS) vulnerability in the bib2html plugin 0.9.3 for WordPress allows remote attackers to inject ar... |
| CVE-2014-3840 | — | — | 3.5% | May 27, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.1... |
| CVE-2014-2720 | — | — | 2.3% | May 27, 2014 | IZArc 4.1.8 displays a file's name on the basis of a ZIP archive's Central Directory entry, but launches this file on th... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now