2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3266 | — | — | 1.2% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote at... |
| CVE-2014-2504 | — | — | 3.0% | May 26, 2014 | EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote a... |
| CVE-2014-2196 | — | — | 2.4% | May 26, 2014 | Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allow... |
| CVE-2014-3284 | — | — | 1.2% | May 25, 2014 | Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service... |
| CVE-2014-0943 | — | — | 2.3% | May 25, 2014 | IBM WebSphere Commerce 6.0 Feature Pack 2 through Feature Pack 5, 7.0.0.0 through 7.0.0.8, and 7.0 Feature Pack 1 throug... |
| CVE-2014-0639 | — | — | 1.2% | May 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer 5.x before GRC 5.4 SP1 P3 allow remote attackers t... |
| CVE-2014-3849 | — | — | 6.0% | May 23, 2014 | The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attac... |
| CVE-2014-3848 | — | — | 9.4% | May 23, 2014 | The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o... |
| CVE-2014-3801 | — | — | 1.6% | May 23, 2014 | OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a pr... |
| CVE-2014-3450 | — | — | 0.4% | May 23, 2014 | Unspecified vulnerability in Panda Gold Protection and Global Protection 2014 7.01.01 and earlier, Internet Security 201... |
| CVE-2014-3442 | — | — | 2.8% | May 23, 2014 | Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malfor... |
| CVE-2014-3789 | — | — | 64.2% | May 22, 2014 | GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary ... |
| CVE-2014-3788 | — | — | 4.0% | May 22, 2014 | Heap-based buffer overflow in the Web Server in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attac... |
| CVE-2014-2948 | — | — | 1.1% | May 22, 2014 | SQL injection vulnerability in workflowenginesoa.asmx in Bizagi BPM Suite through 10.4 allows remote authenticated users... |
| CVE-2014-2947 | — | — | 1.1% | May 22, 2014 | Cross-site scripting (XSS) vulnerability in Login.aspx in Bizagi BPM Suite before 10.3 allows remote attackers to inject... |
| CVE-2014-2938 | — | — | 1.6% | May 22, 2014 | Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control a... |
| CVE-2014-2350 | — | — | 1.3% | May 22, 2014 | Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote at... |
| CVE-2014-2349 | — | — | 0.7% | May 22, 2014 | Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote at... |
| CVE-2014-3831 | — | — | — | May 22, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2014-1346 | — | — | 1.9% | May 22, 2014 | WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which a... |
| CVE-2014-1344 | — | — | 2.1% | May 22, 2014 | WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1343 | — | — | 2.6% | May 22, 2014 | WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1342 | — | — | 2.3% | May 22, 2014 | WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1341 | — | — | 2.3% | May 22, 2014 | WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or ... |
| CVE-2014-1339 | — | — | 2.3% | May 22, 2014 | WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now