2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0867 | — | — | 5.1% | Jul 7, 2014 | rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM A... |
| CVE-2014-0866 | — | — | 5.5% | Jul 7, 2014 | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext c... |
| CVE-2014-0865 | — | — | 5.0% | Jul 7, 2014 | RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-... |
| CVE-2014-0864 | — | — | 2.5% | Jul 7, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5... |
| CVE-2014-0860 | — | — | 1.0% | Jul 7, 2014 | The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrate... |
| CVE-2014-0602 | — | — | 2.9% | Jul 7, 2014 | Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager ... |
| CVE-2014-4721 | — | — | 5.7% | Jul 6, 2014 | The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of th... |
| CVE-2014-4720 | — | — | 1.9% | Jul 6, 2014 | Email::Address module before 1.904 for Perl uses an inefficient regular expression, which allows remote attackers to cau... |
| CVE-2014-4672 | — | — | 2.1% | Jul 3, 2014 | The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors ... |
| CVE-2014-4168 | — | — | 3.8% | Jul 3, 2014 | (1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execu... |
| CVE-2014-3497 | — | — | 2.1% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbi... |
| CVE-2014-0477 | — | — | 3.6% | Jul 3, 2014 | The parse function in Email::Address module before 1.905 for Perl uses an inefficient regular expression, which allows r... |
| CVE-2014-0247 | — | — | 3.9% | Jul 3, 2014 | LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possib... |
| CVE-2014-4719 | — | — | 1.4% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in the login panel (svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 al... |
| CVE-2014-4718 | — | — | 2.3% | Jul 3, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack th... |
| CVE-2014-4717 | — | — | 2.8% | Jul 3, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordP... |
| CVE-2014-4716 | — | — | 2.3% | Jul 3, 2014 | Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authenticatio... |
| CVE-2014-4195 | — | — | 1.4% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to inject arbit... |
| CVE-2014-4002 | — | — | 2.1% | Jul 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web scrip... |
| CVE-2014-3920 | — | — | 0.7% | Jul 3, 2014 | Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentic... |
| CVE-2014-3857 | — | — | 2.2% | Jul 3, 2014 | Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before ... |
| CVE-2014-3538 | — | — | 11.8% | Jul 3, 2014 | file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers... |
| CVE-2014-3149 | — | — | 1.9% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4... |
| CVE-2014-2965 | — | — | 2.5% | Jul 3, 2014 | Cross-site scripting (XSS) vulnerability in auth-settings-x.php in SpamTitan before 6.04 allows remote attackers to inje... |
| CVE-2014-0325 | — | — | 16.1% | Jul 3, 2014 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now