2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2151 | — | — | 1.4% | Jun 18, 2014 | The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated... |
| CVE-2014-2000 | — | — | 1.0% | Jun 18, 2014 | The NTT 050 plus application before 4.2.1 for Android allows attackers to obtain sensitive information by leveraging the... |
| CVE-2014-0910 | — | — | 2.7% | Jun 18, 2014 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 C... |
| CVE-2014-4309 | — | — | 1.0% | Jun 18, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99 allow remote attackers to inject arbitrary web scr... |
| CVE-2014-4308 | — | — | 1.4% | Jun 18, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow... |
| CVE-2014-4307 | — | — | 2.2% | Jun 18, 2014 | SQL injection vulnerability in categories-x.php in WebTitan before 4.04 allows remote attackers to execute arbitrary SQL... |
| CVE-2014-4306 | — | — | 7.6% | Jun 18, 2014 | Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files ... |
| CVE-2014-4305 | — | — | 1.9% | Jun 18, 2014 | Multiple SQL injection vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) 6.5.7 and earlier allow remote ... |
| CVE-2014-4304 | — | — | 1.5% | Jun 18, 2014 | Cross-site scripting (XSS) vulnerability in browse.php in SQL Buddy 1.3.3 and earlier allows remote attackers to inject ... |
| CVE-2014-4303 | — | — | 1.3% | Jun 18, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme 7.x-1.x before 7.x-1.9 for Drupal allow remote au... |
| CVE-2014-4302 | — | — | 1.0% | Jun 18, 2014 | Cross-site scripting (XSS) vulnerability in rating/rating.php in HAM3D Shop Engine allows remote attackers to inject arb... |
| CVE-2014-4301 | — | — | 2.3% | Jun 18, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti ... |
| CVE-2014-3877 | — | — | 1.9% | Jun 18, 2014 | Incomplete blacklist vulnerability in Frams' Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attack... |
| CVE-2014-3876 | — | — | 1.9% | Jun 18, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Frams' Fast File EXchange (F*EX, aka fex) before fex-20140530 all... |
| CVE-2014-4193 | — | — | 2.1% | Jun 17, 2014 | The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during... |
| CVE-2014-4192 | — | — | 1.7% | Jun 17, 2014 | The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for out... |
| CVE-2014-4191 | — | — | 1.7% | Jun 17, 2014 | The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during ... |
| CVE-2014-4040 | — | — | 1.8% | Jun 17, 2014 | snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passw... |
| CVE-2014-4039 | — | — | 0.4% | Jun 17, 2014 | ppc64-diag 2.6.1 uses 0775 permissions for /tmp/diagSEsnap and does not properly restrict permissions for /tmp/diagSEsna... |
| CVE-2014-4038 | — | — | 0.4% | Jun 17, 2014 | ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_supp... |
| CVE-2014-4190 | — | — | 1.5% | Jun 17, 2014 | Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S930... |
| CVE-2014-4189 | — | — | 1.2% | Jun 17, 2014 | Cross-site scripting (XSS) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Perfo... |
| CVE-2014-4188 | — | — | 0.6% | Jun 17, 2014 | Cross-site request forgery (CSRF) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP... |
| CVE-2014-4187 | — | — | 1.4% | Jun 17, 2014 | Cross-site scripting (XSS) vulnerability in signup.php in ClipBucket allows remote attackers to inject arbitrary web scr... |
| CVE-2014-4048 | — | — | 2.8% | Jun 17, 2014 | The PJSIP Channel Driver in Asterisk Open Source before 12.3.1 allows remote attackers to cause a denial of service (dea... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now