2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4689 | — | — | 2.8% | Jul 2, 2014 | Absolute path traversal vulnerability in pkg_edit.php in pfSense before 2.1.4 allows remote attackers to read arbitrary ... |
| CVE-2014-4688 | — | — | 7.0% | Jul 2, 2014 | pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_... |
| CVE-2014-4687 | — | — | 1.7% | Jul 2, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.1.4 allow remote attackers to inject arbitrary w... |
| CVE-2014-3307 | — | — | 1.3% | Jul 2, 2014 | The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to ... |
| CVE-2014-3298 | — | — | 1.6% | Jul 2, 2014 | Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which al... |
| CVE-2014-3297 | — | — | 1.8% | Jul 2, 2014 | Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action... |
| CVE-2014-3074 | — | — | 0.6% | Jul 2, 2014 | The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and co... |
| CVE-2014-3066 | — | — | 2.4% | Jul 2, 2014 | IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containin... |
| CVE-2014-4668 | — | — | 2.8% | Jul 2, 2014 | The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does ... |
| CVE-2014-3100 | — | — | 1.8% | Jul 2, 2014 | Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 al... |
| CVE-2014-3088 | — | — | 2.0% | Jul 1, 2014 | stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenFor... |
| CVE-2014-3477 | MEDIUM | 4 | 0.4% | Jul 1, 2014 | The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error t... |
| CVE-2014-3494 | — | — | 0.7% | Jul 1, 2014 | kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning... |
| CVE-2014-3492 | — | — | 1.5% | Jul 1, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1... |
| CVE-2014-3491 | — | — | 1.5% | Jul 1, 2014 | Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to injec... |
| CVE-2014-4602 | — | — | 1.6% | Jul 1, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in xencarousel-admin.js.php in the XEN Carousel plugin 0.12.2 and ea... |
| CVE-2014-4585 | — | — | 1.6% | Jul 1, 2014 | Cross-site scripting (XSS) vulnerability in the WP-FaceThumb plugin possibly 1.0 and earlier for WordPress allows remote... |
| CVE-2014-4584 | — | — | 1.6% | Jul 1, 2014 | Cross-site scripting (XSS) vulnerability in admin/editFacility.php in the wp-easybooking plugin 1.0.3 and earlier for Wo... |
| CVE-2014-4583 | — | — | 1.6% | Jul 1, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in forms/messages.php in the WP-Contact (wp-contact-sidebar-widget) ... |
| CVE-2014-4575 | — | — | 1.6% | Jul 1, 2014 | Cross-site scripting (XSS) vulnerability in js/window.php in the Wikipop plugin 2.0 and earlier for WordPress allows rem... |
| CVE-2014-4569 | — | — | 2.0% | Jul 1, 2014 | Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2... |
| CVE-2014-4564 | — | — | 1.6% | Jul 1, 2014 | Cross-site scripting (XSS) vulnerability in check.php in the Validated plugin 1.0.2 and earlier for WordPress allows rem... |
| CVE-2014-4556 | — | — | 1.6% | Jul 1, 2014 | Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for eShop plugin 3.7.0 and earlier for... |
| CVE-2014-4545 | — | — | 1.6% | Jul 1, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in pq_dialog.php in the Pro Quoter plugin 1.0 and earlier for WordPr... |
| CVE-2014-4538 | — | — | 1.6% | Jul 1, 2014 | Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allow... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now