2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2067 | — | — | 1.4% | Mar 1, 2014 | Cross-site scripting (XSS) vulnerability in java/hudson/model/Cause.java in Jenkins before 1.551 and LTS before 1.532.2 ... |
| CVE-2014-2059 | — | — | 2.5% | Mar 1, 2014 | Directory traversal vulnerability in the CLI job creation (hudson/cli/CreateJobCommand.java) in Jenkins before 1.551 and... |
| CVE-2014-1888 | — | — | 2.6% | Mar 1, 2014 | Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated... |
| CVE-2014-1695 | — | — | 4.9% | Mar 1, 2014 | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15, ... |
| CVE-2014-1456 | — | — | 1.8% | Mar 1, 2014 | Cross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attack... |
| CVE-2014-1878 | — | — | 3.1% | Feb 28, 2014 | Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and ... |
| CVE-2014-2039 | — | — | 0.5% | Feb 28, 2014 | arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use ... |
| CVE-2014-2038 | — | — | 0.4% | Feb 28, 2014 | The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to ex... |
| CVE-2014-1874 | — | — | 0.6% | Feb 28, 2014 | The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows loc... |
| CVE-2014-1690 | — | — | 3.8% | Feb 28, 2014 | The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sens... |
| CVE-2014-0874 | — | — | 1.4% | Feb 28, 2014 | Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticat... |
| CVE-2014-0774 | — | — | 0.5% | Feb 28, 2014 | Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35,... |
| CVE-2014-0069 | — | — | 0.4% | Feb 28, 2014 | The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached wri... |
| CVE-2014-2103 | — | — | 1.1% | Feb 27, 2014 | Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process o... |
| CVE-2014-0858 | — | — | 0.9% | Feb 27, 2014 | IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to bypass intended access restricti... |
| CVE-2014-0679 | — | — | 2.1% | Feb 27, 2014 | Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows rem... |
| CVE-2014-0333 | — | — | 3.3% | Feb 27, 2014 | The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote at... |
| CVE-2014-2231 | — | — | 0.9% | Feb 27, 2014 | Cross-site scripting (XSS) vulnerability in the API in synetics i-doit pro before 1.2.5 allows remote attackers to injec... |
| CVE-2014-2035 | — | — | 1.2% | Feb 27, 2014 | Cross-site scripting (XSS) vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel ... |
| CVE-2014-1854 | — | — | 5.4% | Feb 27, 2014 | SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free p... |
| CVE-2014-1597 | — | — | 1.5% | Feb 27, 2014 | SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remot... |
| CVE-2014-1223 | — | — | 1.5% | Feb 27, 2014 | Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx in Telligent Evolution before 6.1.19.36103, 7.x be... |
| CVE-2014-0046 | — | — | 1.3% | Feb 27, 2014 | Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1... |
| CVE-2014-2075 | — | — | 3.1% | Feb 27, 2014 | TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authe... |
| CVE-2014-2102 | — | — | 1.3% | Feb 27, 2014 | Cisco Unified Contact Center Express (Unified CCX) does not properly restrict the content of the CCMConfig page, which a... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now