2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0733 | — | — | 1.8% | Feb 20, 2014 | The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier ... |
| CVE-2014-0082 | — | — | 6.2% | Feb 20, 2014 | actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings... |
| CVE-2014-0081 | — | — | 4.0% | Feb 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Ra... |
| CVE-2014-0080 | — | — | 1.3% | Feb 20, 2014 | SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in... |
| CVE-2014-0736 | — | — | 1.0% | Feb 20, 2014 | Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Un... |
| CVE-2014-0735 | — | — | 1.8% | Feb 20, 2014 | Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Ma... |
| CVE-2014-0734 | — | — | 1.2% | Feb 20, 2014 | SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communica... |
| CVE-2014-0732 | — | — | 1.8% | Feb 20, 2014 | The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and ea... |
| CVE-2014-1943 | — | — | 4.9% | Feb 18, 2014 | Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU cons... |
| CVE-2014-2020 | — | — | 2.5% | Feb 18, 2014 | ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive ... |
| CVE-2014-2019 | MEDIUM | 4.6 | 0.5% | Feb 18, 2014 | The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requir... |
| CVE-2014-1903 | — | — | 52.2% | Feb 18, 2014 | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 ... |
| CVE-2014-1861 | — | — | 1.4% | Feb 18, 2014 | The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE... |
| CVE-2014-0627 | — | — | 1.5% | Feb 18, 2014 | The SSLEngine API implementation in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to... |
| CVE-2014-0626 | — | — | 1.9% | Feb 18, 2014 | The (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 make it easier for remote a... |
| CVE-2014-0625 | — | — | 1.8% | Feb 18, 2014 | The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6... |
| CVE-2014-2018 | — | — | 2.0% | Feb 17, 2014 | Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.1... |
| CVE-2014-0814 | — | — | 2.0% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to inject arbitrary web script... |
| CVE-2014-0813 | — | — | 1.1% | Feb 14, 2014 | Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentic... |
| CVE-2014-0332 | — | — | 2.8% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1... |
| CVE-2014-0322 | HIGH | 8.8 | 85.2% | Feb 14, 2014 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v... |
| CVE-2014-1965 | — | — | 1.2% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructu... |
| CVE-2014-1964 | — | — | 1.2% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) compon... |
| CVE-2014-1963 | — | — | 1.6% | Feb 14, 2014 | Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service v... |
| CVE-2014-1962 | — | — | 1.5% | Feb 14, 2014 | Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now