2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2751 | — | — | 1.5% | Apr 10, 2014 | SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access v... |
| CVE-2014-2750 | — | — | — | Apr 10, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2744, CVE-2014-2745. Reason: This candidate is... |
| CVE-2014-2749 | — | — | 1.5% | Apr 10, 2014 | The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and... |
| CVE-2014-2748 | — | — | 1.5% | Apr 10, 2014 | The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or ... |
| CVE-2014-2708 | — | — | 2.0% | Apr 10, 2014 | Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to... |
| CVE-2014-2583 | — | — | 4.1% | Apr 10, 2014 | Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.... |
| CVE-2014-1455 | — | — | 1.3% | Apr 10, 2014 | SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, p... |
| CVE-2014-0331 | — | — | 1.9% | Apr 10, 2014 | Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allo... |
| CVE-2014-2141 | — | — | 1.4% | Apr 10, 2014 | The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initial... |
| CVE-2014-2129 | — | — | 1.7% | Apr 10, 2014 | The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5),... |
| CVE-2014-2128 | — | — | 1.9% | Apr 10, 2014 | The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40)... |
| CVE-2014-2127 | — | — | 11.5% | Apr 10, 2014 | Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 be... |
| CVE-2014-2126 | — | — | 2.1% | Apr 10, 2014 | Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 be... |
| CVE-2014-2544 | — | — | 3.0% | Apr 10, 2014 | Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in ... |
| CVE-2014-0166 | — | — | 8.9% | Apr 10, 2014 | The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does ... |
| CVE-2014-0165 | — | — | 2.4% | Apr 10, 2014 | WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contr... |
| CVE-2014-1729 | — | — | 1.4% | Apr 9, 2014 | Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allo... |
| CVE-2014-1728 | — | — | 1.3% | Apr 9, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 34.0.1847.116 allow attackers to cause a denial of service ... |
| CVE-2014-1727 | — | — | 1.4% | Apr 9, 2014 | Use-after-free vulnerability in content/renderer/renderer_webcolorchooser_impl.h in Google Chrome before 34.0.1847.116 a... |
| CVE-2014-1726 | — | — | 1.4% | Apr 9, 2014 | The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same O... |
| CVE-2014-1725 | — | — | 1.4% | Apr 9, 2014 | The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does n... |
| CVE-2014-1724 | — | — | 1.3% | Apr 9, 2014 | Use-after-free vulnerability in Free(b)soft Laboratory Speech Dispatcher 0.7.1, as used in Google Chrome before 34.0.184... |
| CVE-2014-1723 | — | — | 1.4% | Apr 9, 2014 | The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116 does not properly ha... |
| CVE-2014-1722 | — | — | 1.4% | Apr 9, 2014 | Use-after-free vulnerability in the RenderBlock::addChildIgnoringAnonymousColumnBlocks function in core/rendering/Render... |
| CVE-2014-1721 | — | — | 1.6% | Apr 9, 2014 | Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimization, which allows ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now