2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-2751SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access v...
CVE-2014-2750Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2744, CVE-2014-2745. Reason: This candidate is...
CVE-2014-2749The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and...
CVE-2014-2748The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or ...
CVE-2014-2708Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to...
CVE-2014-2583Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1....
CVE-2014-1455SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, p...
CVE-2014-0331Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allo...
CVE-2014-2141The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initial...
CVE-2014-2129The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5),...
CVE-2014-2128The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40)...
CVE-2014-2127Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 be...
CVE-2014-2126Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 be...
CVE-2014-2544Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in ...
CVE-2014-0166The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does ...
CVE-2014-0165WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contr...
CVE-2014-1729Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allo...
CVE-2014-1728Multiple unspecified vulnerabilities in Google Chrome before 34.0.1847.116 allow attackers to cause a denial of service ...
CVE-2014-1727Use-after-free vulnerability in content/renderer/renderer_webcolorchooser_impl.h in Google Chrome before 34.0.1847.116 a...
CVE-2014-1726The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same O...
CVE-2014-1725The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does n...
CVE-2014-1724Use-after-free vulnerability in Free(b)soft Laboratory Speech Dispatcher 0.7.1, as used in Google Chrome before 34.0.184...
CVE-2014-1723The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116 does not properly ha...
CVE-2014-1722Use-after-free vulnerability in the RenderBlock::addChildIgnoringAnonymousColumnBlocks function in core/rendering/Render...
CVE-2014-1721Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimization, which allows ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now