2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9635 | — | — | 2.7% | Sep 12, 2017 | Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41... |
| CVE-2014-9634 | — | — | 2.7% | Sep 12, 2017 | Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it ... |
| CVE-2014-9624 | — | — | 3.0% | Sep 12, 2017 | CAPTCHA bypass vulnerability in MantisBT before 1.2.19. |
| CVE-2014-9565 | — | — | 0.6% | Sep 7, 2017 | Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switc... |
| CVE-2014-6438 | — | — | 4.1% | Sep 6, 2017 | The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service ... |
| CVE-2014-8677 | — | — | 3.5% | Aug 31, 2017 | The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and... |
| CVE-2014-8676 | — | — | 40.8% | Aug 31, 2017 | Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke... |
| CVE-2014-8675 | — | — | 12.5% | Aug 31, 2017 | Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all... |
| CVE-2014-9497 | — | — | 2.3% | Aug 29, 2017 | Buffer overflow in mpg123 before 1.18.0. |
| CVE-2014-8872 | — | — | 1.5% | Aug 29, 2017 | Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after... |
| CVE-2014-8393 | — | — | 8.3% | Aug 29, 2017 | DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel... |
| CVE-2014-8163 | — | — | 1.5% | Aug 28, 2017 | Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5. |
| CVE-2014-9558 | — | — | 3.7% | Aug 28, 2017 | Multiple SQL injection vulnerabilities in SmartCMS v.2. |
| CVE-2014-9557 | MEDIUM | 6.1 | 1.0% | Aug 28, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2. |
| CVE-2014-9514 | — | — | 0.8% | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5. |
| CVE-2014-9513 | — | — | 3.7% | Aug 28, 2017 | Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code. |
| CVE-2014-9483 | — | — | 2.8% | Aug 28, 2017 | Emacs 24.4 allows remote attackers to bypass security restrictions. |
| CVE-2014-9469 | — | — | 1.4% | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3. |
| CVE-2014-9312 | — | — | 45.4% | Aug 28, 2017 | Unrestricted File Upload vulnerability in Photo Gallery 1.2.5. |
| CVE-2014-8900 | — | — | 0.6% | Aug 28, 2017 | Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6... |
| CVE-2014-8871 | — | — | 4.1% | Aug 28, 2017 | Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 an... |
| CVE-2014-8753 | — | — | 1.5% | Aug 28, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Cit-e-Net Cit-e-Access 6. |
| CVE-2014-8428 | — | — | 2.4% | Aug 28, 2017 | Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key. |
| CVE-2014-8426 | — | — | 2.2% | Aug 28, 2017 | Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015. |
| CVE-2014-8168 | — | — | 0.3% | Aug 28, 2017 | Red Hat Satellite 6 allows local users to access mongod and delete pulp_database. |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now