2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-1296 | — | — | 1.9% | Apr 23, 2014 | CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Coo... |
| CVE-2014-1295 | — | — | 0.9% | Apr 23, 2014 | Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does ... |
| CVE-2014-2899 | — | — | 1.8% | Apr 22, 2014 | wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a re... |
| CVE-2014-2900 | — | — | 1.0% | Apr 22, 2014 | wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows... |
| CVE-2014-2892 | — | — | 6.1% | Apr 22, 2014 | Heap-based buffer overflow in the get_answer function in mmsh.c in libmms before 0.6.4 allows remote attackers to execut... |
| CVE-2014-2890 | — | — | 1.2% | Apr 22, 2014 | Cross-site scripting (XSS) vulnerability in the wrap_html function in MyID.php in phpMyID 0.9 allows remote attackers to... |
| CVE-2014-2737 | — | — | 1.2% | Apr 22, 2014 | SQL injection vulnerability in the get_active_session function in the KTAPI_UserSession class in webservice/clienttools/... |
| CVE-2014-2659 | — | — | 0.6% | Apr 22, 2014 | Cross-site request forgery (CSRF) vulnerability in the admin UI in Papercut MF and NG before 14.1 (Build 26983) allows r... |
| CVE-2014-2654 | — | — | 1.1% | Apr 22, 2014 | Multiple SQL injection vulnerabilities in MobFox mAdserve 2.0 and earlier allow remote authenticated users to execute ar... |
| CVE-2014-1615 | — | — | 0.6% | Apr 22, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack... |
| CVE-2014-2925 | — | — | 1.2% | Apr 22, 2014 | Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers w... |
| CVE-2014-2735 | — | — | 0.8% | Apr 22, 2014 | WinSCP before 5.5.3, when FTP with TLS is used, does not verify that the server hostname matches a domain name in the su... |
| CVE-2014-2719 | — | — | 1.1% | Apr 22, 2014 | Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator s... |
| CVE-2014-2341 | — | — | 5.8% | Apr 22, 2014 | Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID... |
| CVE-2014-2269 | — | — | 15.7% | Apr 22, 2014 | modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for... |
| CVE-2014-1216 | — | — | 3.9% | Apr 22, 2014 | FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAN... |
| CVE-2014-0173 | — | — | 2.2% | Apr 22, 2014 | The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3... |
| CVE-2014-2922 | — | — | 2.9% | Apr 21, 2014 | The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 doe... |
| CVE-2014-2921 | — | — | 7.3% | Apr 21, 2014 | The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 doe... |
| CVE-2014-0932 | — | — | 0.9% | Apr 21, 2014 | Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.5 before HF105 and Sterling Selling and Fulf... |
| CVE-2014-0361 | — | — | 0.3% | Apr 21, 2014 | The default configuration of IBM 4690 OS, as used in Toshiba Global Commerce Solutions 4690 POS and other products, hash... |
| CVE-2014-2665 | — | — | 1.1% | Apr 20, 2014 | includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x bef... |
| CVE-2014-1517 | — | — | 1.3% | Apr 20, 2014 | The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authe... |
| CVE-2014-2155 | — | — | 1.7% | Apr 19, 2014 | The DHCPv6 server module in Cisco CNS Network Registrar 7.1 allows remote attackers to cause a denial of service (daemon... |
| CVE-2014-2733 | — | — | 2.6% | Apr 19, 2014 | Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a denial of service (web-interface outage) via craf... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now