2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3778 | — | — | 1.9% | Jun 19, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboar... |
| CVE-2014-4329 | — | — | 1.2% | Jun 19, 2014 | Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitra... |
| CVE-2014-2962 | — | — | 47.1% | Jun 19, 2014 | Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware befor... |
| CVE-2014-2782 | — | — | 22.4% | Jun 19, 2014 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ... |
| CVE-2014-2611 | — | — | 11.9% | Jun 19, 2014 | Directory traversal vulnerability in the fndwar web application in HP Executive Scorecard 9.40 and 9.41 allows remote au... |
| CVE-2014-2610 | — | — | 5.3% | Jun 19, 2014 | Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 ... |
| CVE-2014-2609 | — | — | 12.9% | Jun 19, 2014 | The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows r... |
| CVE-2014-2001 | — | — | 0.6% | Jun 19, 2014 | The East Japan Railway Company JR East Japan application before 1.2.0 for Android does not verify X.509 certificates fro... |
| CVE-2014-4286 | — | — | — | Jun 18, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4286. Reason: This candidate is a duplicate of... |
| CVE-2014-4153 | — | — | 7.4% | Jun 18, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a craft... |
| CVE-2014-4152 | — | — | 5.8% | Jun 18, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a cra... |
| CVE-2014-4151 | — | — | 7.3% | Jun 18, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execu... |
| CVE-2014-4049 | — | — | 10.9% | Jun 18, 2014 | Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote... |
| CVE-2014-4021 | — | — | 0.7% | Jun 18, 2014 | Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to... |
| CVE-2014-1652 | — | — | 1.7% | Jun 18, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 a... |
| CVE-2014-1651 | — | — | 2.0% | Jun 18, 2014 | SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allow... |
| CVE-2014-1650 | — | — | 1.4% | Jun 18, 2014 | SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remo... |
| CVE-2014-0599 | — | — | 2.0% | Jun 18, 2014 | Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Upda... |
| CVE-2014-0598 | — | — | 2.5% | Jun 18, 2014 | Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151... |
| CVE-2014-4174 | — | — | 5.9% | Jun 18, 2014 | wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitr... |
| CVE-2014-4020 | — | — | 1.4% | Jun 18, 2014 | The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.... |
| CVE-2014-3013 | — | — | 0.9% | Jun 18, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Curam Social Program Management 4.5 SP10 through 6.0.5.4 allo... |
| CVE-2014-3012 | — | — | 1.0% | Jun 18, 2014 | Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote auth... |
| CVE-2014-2949 | — | — | 1.4% | Jun 18, 2014 | SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated us... |
| CVE-2014-2779 | — | — | 13.4% | Jun 18, 2014 | mpengine.dll in Microsoft Malware Protection Engine before 1.1.10701.0 allows remote attackers to cause a denial of serv... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now