2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0674 | — | — | 1.6% | Jan 24, 2014 | Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which... |
| CVE-2014-1242 | — | — | 1.0% | Jan 23, 2014 | Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof ... |
| CVE-2014-0494 | — | — | 4.8% | Jan 23, 2014 | Adobe Digital Editions 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption ... |
| CVE-2014-0675 | — | — | 1.6% | Jan 23, 2014 | The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate ... |
| CVE-2014-0979 | — | — | 0.4% | Jan 23, 2014 | The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle... |
| CVE-2014-0006 | — | — | 1.9% | Jan 23, 2014 | The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows ... |
| CVE-2014-0807 | — | — | 1.6% | Jan 22, 2014 | data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and earlier, and 2.11.0 through 2.12.2, all... |
| CVE-2014-0806 | — | — | 1.1% | Jan 22, 2014 | The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for ... |
| CVE-2014-0677 | — | — | 2.1% | Jan 22, 2014 | The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service ... |
| CVE-2014-0676 | — | — | 0.4% | Jan 22, 2014 | Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bu... |
| CVE-2014-0662 | — | — | 1.9% | Jan 22, 2014 | The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a deni... |
| CVE-2014-0661 | — | — | 2.3% | Jan 22, 2014 | The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42... |
| CVE-2014-0660 | — | — | 1.9% | Jan 22, 2014 | Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-c... |
| CVE-2014-1637 | — | — | 6.9% | Jan 22, 2014 | Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which a... |
| CVE-2014-1636 | — | — | 3.9% | Jan 22, 2014 | Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe... |
| CVE-2014-0672 | — | — | 2.1% | Jan 22, 2014 | The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows rem... |
| CVE-2014-0671 | — | — | 2.3% | Jan 22, 2014 | Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and con... |
| CVE-2014-0670 | — | — | 2.2% | Jan 22, 2014 | Cross-site scripting (XSS) vulnerability in the Search and Play interface in Cisco MediaSense allows remote attackers to... |
| CVE-2014-0669 | — | — | 1.8% | Jan 22, 2014 | The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series d... |
| CVE-2014-1620 | — | — | 1.2% | Jan 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in add.php in HIOX Guest Book (HGB) 5.0 allow remote attackers to in... |
| CVE-2014-1619 | — | — | 2.3% | Jan 21, 2014 | Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQ... |
| CVE-2014-1618 | — | — | 3.3% | Jan 21, 2014 | Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com... |
| CVE-2014-1452 | — | — | 1.9% | Jan 21, 2014 | Stack-based buffer overflow in lib/snmpagent.c in bsnmpd, as used in FreeBSD 8.3 through 10.0, allows remote attackers t... |
| CVE-2014-0753 | — | — | 2.5% | Jan 21, 2014 | Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a d... |
| CVE-2014-0010 | — | — | 1.1% | Jan 20, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x bef... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now