2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0080 | — | — | 1.3% | Feb 20, 2014 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in... |
| CVE-2014-0736 | — | — | 1.0% | Feb 20, 2014 | Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Un... |
| CVE-2014-0735 | — | — | 1.8% | Feb 20, 2014 | Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Ma... |
| CVE-2014-0734 | — | — | 1.2% | Feb 20, 2014 | SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communica... |
| CVE-2014-0732 | — | — | 1.8% | Feb 20, 2014 | The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and ea... |
| CVE-2014-1943 | — | — | 4.9% | Feb 18, 2014 | Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU cons... |
| CVE-2014-2020 | — | — | 2.5% | Feb 18, 2014 | ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive ... |
| CVE-2014-1903 | — | — | 52.2% | Feb 18, 2014 | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 ... |
| CVE-2014-1861 | — | — | 1.4% | Feb 18, 2014 | The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE... |
| CVE-2014-0627 | — | — | 1.5% | Feb 18, 2014 | The SSLEngine API implementation in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to... |
| CVE-2014-0626 | — | — | 1.9% | Feb 18, 2014 | The (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 make it easier for remote a... |
| CVE-2014-0625 | — | — | 1.8% | Feb 18, 2014 | The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6... |
| CVE-2014-2018 | — | — | 2.0% | Feb 17, 2014 | Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.1... |
| CVE-2014-0814 | — | — | 2.0% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to inject arbitrary web script... |
| CVE-2014-0813 | — | — | 1.1% | Feb 14, 2014 | Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentic... |
| CVE-2014-0332 | — | — | 2.8% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1... |
| CVE-2014-1965 | — | — | 1.2% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructu... |
| CVE-2014-1964 | — | — | 1.2% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) compon... |
| CVE-2014-1963 | — | — | 1.6% | Feb 14, 2014 | Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service v... |
| CVE-2014-1962 | — | — | 1.5% | Feb 14, 2014 | Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to... |
| CVE-2014-1961 | — | — | 2.1% | Feb 14, 2014 | Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path info... |
| CVE-2014-1960 | — | — | 1.4% | Feb 14, 2014 | The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensiti... |
| CVE-2014-1950 | — | — | 0.4% | Feb 14, 2014 | Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded t... |
| CVE-2014-1948 | — | — | 0.3% | Feb 14, 2014 | OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL... |
| CVE-2014-1921 | — | — | 1.6% | Feb 14, 2014 | parcimonie before 0.8.1, when using a large keyring, sleeps for the same amount of time between fetches, which allows at... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now