2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0802 | — | — | 1.1% | Jan 12, 2014 | Directory traversal vulnerability in the aokitaka ZIP with Pass application 4.5.7 and earlier, and ZIP with Pass Pro app... |
| CVE-2014-0659 | — | — | 73.8% | Jan 12, 2014 | The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x... |
| CVE-2014-0618 | — | — | 3.6% | Jan 11, 2014 | Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X... |
| CVE-2014-0978 | — | — | 4.9% | Jan 10, 2014 | Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to h... |
| CVE-2014-0977 | — | — | 2.4% | Jan 10, 2014 | Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5... |
| CVE-2014-1408 | — | — | 1.5% | Jan 10, 2014 | The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which... |
| CVE-2014-1407 | — | — | 1.2% | Jan 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow... |
| CVE-2014-1406 | — | — | 1.0% | Jan 10, 2014 | CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 a... |
| CVE-2014-1405 | — | — | 1.2% | Jan 10, 2014 | Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attac... |
| CVE-2014-0664 | — | — | 2.8% | Jan 10, 2014 | The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) vi... |
| CVE-2014-0663 | — | — | 1.5% | Jan 10, 2014 | Cross-site scripting (XSS) vulnerability in the web framework in Cisco Secure Access Control System (ACS) allows remote ... |
| CVE-2014-0658 | — | — | 2.7% | Jan 10, 2014 | Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP head... |
| CVE-2014-1236 | — | — | 6.1% | Jan 10, 2014 | Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to ha... |
| CVE-2014-1234 | — | — | 0.5% | Jan 10, 2014 | The paratrooper-newrelic gem 1.0.1 for Ruby allows local users to obtain the X-Api-Key value by listing the curl process... |
| CVE-2014-1233 | — | — | 0.4% | Jan 10, 2014 | The paratrooper-pingdom gem 1.0.0 for Ruby allows local users to obtain the App-Key, username, and password values by li... |
| CVE-2014-0752 | — | — | 1.6% | Jan 9, 2014 | The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via ... |
| CVE-2014-0657 | — | — | 2.1% | Jan 8, 2014 | The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly hand... |
| CVE-2014-0656 | — | — | 2.0% | Jan 8, 2014 | Cisco Context Directory Agent (CDA) allows remote authenticated users to trigger the omission of certain user-interface ... |
| CVE-2014-0655 | — | — | 1.5% | Jan 8, 2014 | The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers t... |
| CVE-2014-0654 | — | — | 2.3% | Jan 8, 2014 | Cisco Context Directory Agent (CDA) allows remote attackers to modify the cache via a replay attack involving crafted RA... |
| CVE-2014-0653 | — | — | 6.9% | Jan 8, 2014 | The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers t... |
| CVE-2014-0652 | — | — | 2.2% | Jan 8, 2014 | Cross-site scripting (XSS) vulnerability in the Mappings page in Cisco Context Directory Agent (CDA) allows remote attac... |
| CVE-2014-0651 | — | — | 1.8% | Jan 8, 2014 | The administrative interface in Cisco Context Directory Agent (CDA) does not properly enforce authorization requirements... |
| CVE-2014-1232 | — | — | 2.0% | Jan 8, 2014 | Cross-site scripting (XSS) vulnerability in the Foliopress WYSIWYG plugin before 2.6.8.5 for WordPress allows remote att... |
| CVE-2014-0621 | — | — | 1.0% | Jan 8, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow rem... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now