2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3456 | — | — | 0.9% | May 13, 2014 | Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to... |
| CVE-2014-3246 | — | — | 1.3% | May 13, 2014 | SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via th... |
| CVE-2014-2989 | — | — | 1.2% | May 13, 2014 | Cross-site request forgery (CSRF) vulnerability in Open Assessment Technologies TAO 2.5.6 allows remote attackers to hij... |
| CVE-2014-3455 | — | — | 0.6% | May 12, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm... |
| CVE-2014-3454 | — | — | 0.6% | May 12, 2014 | Cross-site request forgery (CSRF) vulnerability in Special:CreateCategory in the SemanticForms extension for MediaWiki b... |
| CVE-2014-3243 | — | — | 2.7% | May 12, 2014 | SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denia... |
| CVE-2014-3242 | — | — | 1.8% | May 12, 2014 | SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declarati... |
| CVE-2014-2928 | — | — | 39.1% | May 12, 2014 | The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5... |
| CVE-2014-2301 | — | — | 1.5% | May 12, 2014 | OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an ob... |
| CVE-2014-3145 | — | — | 0.6% | May 11, 2014 | The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kerne... |
| CVE-2014-3144 | — | — | 0.6% | May 11, 2014 | The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/co... |
| CVE-2014-3122 | — | — | 0.5% | May 11, 2014 | The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages ... |
| CVE-2014-1738 | — | — | 0.5% | May 11, 2014 | The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict acc... |
| CVE-2014-1737 | — | — | 0.5% | May 11, 2014 | The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error ... |
| CVE-2014-2603 | — | — | 1.2% | May 10, 2014 | Unspecified vulnerability on HP 8/20q switches, SN6000 switches, and 8Gb Simple SAN Connection Kit with firmware before ... |
| CVE-2014-1991 | — | — | 1.2% | May 9, 2014 | Open redirect vulnerability in WebPlatform / AppFramework 6.0 through 7.2 in NTT DATA INTRAMART intra-mart allows remote... |
| CVE-2014-0946 | — | — | 1.8% | May 9, 2014 | The RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, an... |
| CVE-2014-0945 | — | — | 1.2% | May 9, 2014 | Cross-site scripting (XSS) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager... |
| CVE-2014-0944 | — | — | 0.7% | May 9, 2014 | Cross-site request forgery (CSRF) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision ... |
| CVE-2014-3214 | — | — | 17.3% | May 9, 2014 | The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers... |
| CVE-2014-0913 | — | — | 1.8% | May 9, 2014 | Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remot... |
| CVE-2014-2854 | — | — | 0.9% | May 8, 2014 | Cross-site scripting (XSS) vulnerability in the SemanticTitle extension before 1.1.0 for MediaWiki allows remote attacke... |
| CVE-2014-3207 | — | — | 1.9% | May 8, 2014 | Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject a... |
| CVE-2014-3123 | — | — | 1.6% | May 8, 2014 | Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for... |
| CVE-2014-3115 | — | — | 1.2% | May 8, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now