2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4649 | — | — | 1.0% | Jun 28, 2014 | SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authen... |
| CVE-2014-4648 | — | — | 1.5% | Jun 28, 2014 | Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure." |
| CVE-2014-2613 | — | — | 3.6% | Jun 28, 2014 | Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x b... |
| CVE-2014-2612 | — | — | 6.8% | Jun 28, 2014 | Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x b... |
| CVE-2014-3881 | — | — | 0.6% | Jun 28, 2014 | Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to ... |
| CVE-2014-2006 | — | — | 1.1% | Jun 28, 2014 | Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject ... |
| CVE-2014-0891 | — | — | 2.1% | Jun 28, 2014 | IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remo... |
| CVE-2014-3011 | — | — | 1.0% | Jun 27, 2014 | IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified ... |
| CVE-2014-3433 | — | — | 2.0% | Jun 27, 2014 | Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allow... |
| CVE-2014-3432 | — | — | 2.0% | Jun 27, 2014 | Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allow... |
| CVE-2014-4645 | — | — | 1.5% | Jun 25, 2014 | Cross-site scripting (XSS) vulnerability in dhcpinfo.html in D-link DSL-2760U-E1 allows remote attackers to inject arbit... |
| CVE-2014-4644 | — | — | 1.3% | Jun 25, 2014 | SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execut... |
| CVE-2014-4643 | — | — | 8.8% | Jun 25, 2014 | Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a den... |
| CVE-2014-4030 | — | — | 2.9% | Jun 25, 2014 | Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attacke... |
| CVE-2014-4617 | — | — | 3.3% | Jun 25, 2014 | The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent a... |
| CVE-2014-4349 | — | — | 2.1% | Jun 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow rem... |
| CVE-2014-4348 | — | — | 1.5% | Jun 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to... |
| CVE-2014-3882 | — | — | 1.1% | Jun 25, 2014 | Cross-site request forgery (CSRF) vulnerability in the Login rebuilder plugin before 1.2.0 for WordPress allows remote a... |
| CVE-2014-3299 | — | — | 3.1% | Jun 25, 2014 | Cisco IOS allows remote authenticated users to cause a denial of service (device reload) via malformed IPsec packets, ak... |
| CVE-2014-2005 | MEDIUM | 6.8 | 0.5% | Jun 25, 2014 | Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentic... |
| CVE-2014-0206 | — | — | 0.4% | Jun 25, 2014 | Array index error in the aio_read_events_ring function in fs/aio.c in the Linux kernel through 3.15.1 allows local users... |
| CVE-2014-3493 | — | — | 7.3% | Jun 23, 2014 | The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote ... |
| CVE-2014-0244 | — | — | 20.5% | Jun 23, 2014 | The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remot... |
| CVE-2014-4508 | — | — | 0.4% | Jun 23, 2014 | arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled ... |
| CVE-2014-4171 | — | — | 0.4% | Jun 23, 2014 | mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now