2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1731 | — | — | 3.2% | Apr 26, 2014 | core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Win... |
| CVE-2014-1730 | — | — | 3.2% | Apr 26, 2014 | Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not... |
| CVE-2014-2993 | — | — | 0.7% | Apr 26, 2014 | The Birebin.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-mid... |
| CVE-2014-2992 | — | — | 0.6% | Apr 26, 2014 | The Misli.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middl... |
| CVE-2014-0350 | — | — | 1.2% | Apr 26, 2014 | The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-t... |
| CVE-2014-2996 | — | — | 10.2% | Apr 25, 2014 | XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administr... |
| CVE-2014-2579 | — | — | 6.2% | Apr 25, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers ... |
| CVE-2014-2729 | — | — | 1.0% | Apr 25, 2014 | Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated ... |
| CVE-2014-2984 | — | — | — | Apr 25, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2650. Reason: This candidate is a reservation ... |
| CVE-2014-2909 | — | — | 2.4% | Apr 25, 2014 | CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remo... |
| CVE-2014-2908 | — | — | 20.9% | Apr 25, 2014 | Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x... |
| CVE-2014-0780 | CRITICAL | 9.8 | 74.5% | Apr 25, 2014 | Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers t... |
| CVE-2014-0769 | — | — | 2.1% | Apr 25, 2014 | The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion ... |
| CVE-2014-0760 | — | — | 3.1% | Apr 25, 2014 | The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion... |
| CVE-2014-2734 | — | — | 5.3% | Apr 24, 2014 | The openssl extension in Ruby 2.x does not properly maintain the state of process memory after a file is reopened, which... |
| CVE-2014-2601 | — | — | 4.0% | Apr 24, 2014 | The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of servi... |
| CVE-2014-2915 | — | — | 0.6% | Apr 24, 2014 | Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest... |
| CVE-2014-2736 | — | — | 1.3% | Apr 24, 2014 | Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL ... |
| CVE-2014-0188 | — | — | 1.7% | Apr 24, 2014 | The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentic... |
| CVE-2014-2907 | — | — | 2.1% | Apr 24, 2014 | The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 doe... |
| CVE-2014-2393 | — | — | 0.9% | Apr 24, 2014 | Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 ... |
| CVE-2014-2392 | — | — | 1.1% | Apr 24, 2014 | The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 be... |
| CVE-2014-2391 | — | — | 1.1% | Apr 24, 2014 | The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.... |
| CVE-2014-0360 | — | — | — | Apr 23, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2741. Reason: This candidate is a duplicate of... |
| CVE-2014-1647 | — | — | 0.7% | Apr 23, 2014 | Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly ... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now