2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4159 | — | — | 1.3% | Jun 13, 2014 | Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attacker... |
| CVE-2014-4158 | — | — | 14.3% | Jun 13, 2014 | Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req... |
| CVE-2014-3814 | — | — | 1.3% | Jun 13, 2014 | The Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS loo... |
| CVE-2014-3813 | — | — | 1.3% | Jun 13, 2014 | Unspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configur... |
| CVE-2014-3812 | — | — | 0.7% | Jun 13, 2014 | The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos ... |
| CVE-2014-3805 | — | — | 13.1% | Jun 13, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a... |
| CVE-2014-3804 | — | — | 73.0% | Jun 13, 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a... |
| CVE-2014-2303 | — | — | 2.6% | Jun 13, 2014 | Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and... |
| CVE-2014-3859 | — | — | 7.0% | Jun 13, 2014 | libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a deni... |
| CVE-2014-4037 | — | — | 2.9% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php ... |
| CVE-2014-4036 | — | — | 1.0% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to in... |
| CVE-2014-4035 | — | — | 3.3% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0... |
| CVE-2014-4034 | — | — | 6.3% | Jun 11, 2014 | SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com... |
| CVE-2014-4033 | — | — | 3.3% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows ... |
| CVE-2014-4032 | — | — | 1.9% | Jun 11, 2014 | Cross-site scripting (XSS) vulnerability in apps/app_comment/form_comment.php in Fiyo CMS 1.5.7 allows remote attackers ... |
| CVE-2014-3980 | — | — | 0.4% | Jun 11, 2014 | libfep 0.0.5 before 0.1.0 does not properly use UNIX domain sockets in the abstract namespace, which allows local users ... |
| CVE-2014-3970 | — | — | 1.5% | Jun 11, 2014 | The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote ... |
| CVE-2014-3915 | — | — | 3.1% | Jun 11, 2014 | The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to ... |
| CVE-2014-3911 | — | — | 5.6% | Jun 11, 2014 | Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to th... |
| CVE-2014-3850 | — | — | 1.0% | Jun 11, 2014 | Cross-site request forgery (CSRF) vulnerability in the Member Approval plugin 131109 for WordPress allows remote attacke... |
| CVE-2014-3782 | — | — | 1.2% | Jun 11, 2014 | Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear ... |
| CVE-2014-3781 | — | — | 2.2% | Jun 11, 2014 | The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass a... |
| CVE-2014-3004 | — | — | 7.8% | Jun 11, 2014 | The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct... |
| CVE-2014-2978 | — | — | 6.1% | Jun 11, 2014 | The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers ... |
| CVE-2014-2977 | — | — | 6.8% | Jun 11, 2014 | Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in D... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now