2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0363 | — | — | 1.2% | Apr 30, 2014 | The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints... |
| CVE-2014-0114 | — | — | 95.8% | Apr 30, 2014 | Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o... |
| CVE-2014-2853 | — | — | 2.4% | Apr 29, 2014 | Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before... |
| CVE-2014-0088 | — | — | 8.7% | Apr 29, 2014 | The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platf... |
| CVE-2014-2185 | — | — | 0.9% | Apr 29, 2014 | The Call Detail Records (CDR) Management component in Cisco Unified Communications Manager (Unified CM) allows remote au... |
| CVE-2014-2184 | — | — | 1.2% | Apr 29, 2014 | The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers t... |
| CVE-2014-2183 | — | — | 1.3% | Apr 29, 2014 | The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a d... |
| CVE-2014-2182 | — | — | 0.7% | Apr 29, 2014 | Cisco Adaptive Security Appliance (ASA) Software, when DHCPv6 replay is configured, allows remote attackers to cause a d... |
| CVE-2014-2180 | — | — | 0.8% | Apr 29, 2014 | The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which ... |
| CVE-2014-1843 | — | — | 4.7% | Apr 29, 2014 | Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke... |
| CVE-2014-1842 | — | — | 4.8% | Apr 29, 2014 | Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke... |
| CVE-2014-1841 | — | — | 4.9% | Apr 29, 2014 | Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke... |
| CVE-2014-0515 | — | — | 94.5% | Apr 29, 2014 | Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS ... |
| CVE-2014-0113 | — | — | 78.3% | Apr 29, 2014 | CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict ... |
| CVE-2014-0112 | — | — | 97.9% | Apr 29, 2014 | ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all... |
| CVE-2014-3008 | — | — | 7.0% | Apr 28, 2014 | Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacte... |
| CVE-2014-2986 | — | — | 0.6% | Apr 28, 2014 | The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen ... |
| CVE-2014-2980 | — | — | 1.7% | Apr 28, 2014 | Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file ... |
| CVE-2014-2846 | — | — | 8.8% | Apr 28, 2014 | Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmw... |
| CVE-2014-2715 | — | — | 1.1% | Apr 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in vwrooms\templates\logout.tpl.php in the VideoWhisper Webcam plugi... |
| CVE-2014-2658 | — | — | 1.3% | Apr 28, 2014 | Unspecified vulnerability in Papercut MF and NG before 14.1 (Build 26983) allows attacker to cause a denial of service v... |
| CVE-2014-2657 | — | — | 1.1% | Apr 28, 2014 | Unspecified vulnerability in the print release functionality in PaperCut MF before 14.1 (Build 26983) has unknown impact... |
| CVE-2014-2383 | — | — | 39.4% | Apr 28, 2014 | dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo... |
| CVE-2014-2042 | — | — | 2.2% | Apr 28, 2014 | Unrestricted file upload vulnerability in the Manage Project functionality in Livetecs Timelive before 6.5.1 allows remo... |
| CVE-2014-1217 | — | — | 1.5% | Apr 28, 2014 | Livetecs Timelive before 6.2.8 does not properly restrict access to systemsetting.aspx, which allows remote attackers to... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now