2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0497 | CRITICAL | 9.8 | 99.9% | Feb 5, 2014 | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Ma... |
| CVE-2014-1458 | — | — | 0.8% | Feb 4, 2014 | Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier al... |
| CVE-2014-1694 | — | — | 1.5% | Feb 4, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in (1) CustomerPreferences.pm, (2) CustomerTicketMessage.pm, ... |
| CVE-2014-1471 | — | — | 1.8% | Feb 4, 2014 | SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System... |
| CVE-2014-0019 | — | — | 0.4% | Feb 4, 2014 | Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a... |
| CVE-2014-0834 | — | — | 1.2% | Feb 4, 2014 | IBM General Parallel File System (GPFS) 3.4 through 3.4.0.27 and 3.5 through 3.5.0.16 allows attackers to cause a denial... |
| CVE-2014-0686 | — | — | 0.3% | Feb 4, 2014 | Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges... |
| CVE-2014-0329 | — | — | 8.5% | Feb 4, 2014 | The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account... |
| CVE-2014-0015 | — | — | 5.6% | Feb 2, 2014 | cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, w... |
| CVE-2014-0833 | — | — | 1.1% | Feb 1, 2014 | The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-inter... |
| CVE-2014-0832 | — | — | 0.8% | Feb 1, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financi... |
| CVE-2014-0831 | — | — | 0.6% | Feb 1, 2014 | Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 befo... |
| CVE-2014-0830 | — | — | 1.4% | Feb 1, 2014 | Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction M... |
| CVE-2014-0812 | — | — | 1.2% | Feb 1, 2014 | Cross-site scripting (XSS) vulnerability in KENT-WEB Joyful Note 2.8 and earlier, when Internet Explorer 7 or earlier is... |
| CVE-2014-0001 | — | — | 6.4% | Jan 31, 2014 | Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a d... |
| CVE-2014-1204 | — | — | 4.3% | Jan 31, 2014 | SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated user... |
| CVE-2014-0757 | — | — | 3.2% | Jan 31, 2014 | Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of servi... |
| CVE-2014-1610 | — | — | 42.8% | Jan 30, 2014 | MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is... |
| CVE-2014-1837 | — | — | 1.2% | Jan 30, 2014 | Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allo... |
| CVE-2014-1612 | — | — | 2.5% | Jan 30, 2014 | Cross-site scripting (XSS) vulnerability in login.esp in the Web Management Interface in Media5 Mediatrix 4402 VoIP Gate... |
| CVE-2014-1611 | — | — | 2.2% | Jan 30, 2014 | Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote at... |
| CVE-2014-0793 | — | — | 1.8% | Jan 30, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for J... |
| CVE-2014-0838 | — | — | 1.5% | Jan 30, 2014 | The AutoUpdate package before 6.4 for IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to execute ar... |
| CVE-2014-0837 | — | — | 0.7% | Jan 30, 2014 | The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL serve... |
| CVE-2014-0836 | — | — | 1.3% | Jan 30, 2014 | Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to inje... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now