2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6120 | — | — | 5.1% | Apr 12, 2018 | IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2,... |
| CVE-2014-6633 | — | — | 2.6% | Apr 12, 2018 | The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7,... |
| CVE-2014-3999 | — | — | 2.6% | Apr 10, 2018 | The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge o... |
| CVE-2014-3114 | — | — | 3.6% | Apr 10, 2018 | The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to e... |
| CVE-2014-2078 | — | — | 1.3% | Apr 10, 2018 | The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive informatio... |
| CVE-2014-1946 | — | — | 2.6% | Apr 10, 2018 | OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypa... |
| CVE-2014-1889 | — | — | 10.8% | Apr 10, 2018 | The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain... |
| CVE-2014-1400 | — | — | 1.5% | Apr 10, 2018 | The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users ... |
| CVE-2014-1399 | — | — | 1.4% | Apr 10, 2018 | The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate... |
| CVE-2014-1398 | — | — | 1.5% | Apr 10, 2018 | The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticate... |
| CVE-2014-0158 | — | — | 1.8% | Apr 10, 2018 | Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause ... |
| CVE-2014-1226 | — | — | 0.4% | Apr 6, 2018 | The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permission... |
| CVE-2014-5072 | — | — | 0.9% | Apr 6, 2018 | Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote... |
| CVE-2014-5034 | — | — | 1.1% | Apr 6, 2018 | Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remo... |
| CVE-2014-2359 | — | — | 1.5% | Apr 6, 2018 | OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or s... |
| CVE-2014-3413 | — | — | 2.2% | Apr 5, 2018 | The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, w... |
| CVE-2014-9959 | — | — | 1.1% | Apr 4, 2018 | An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel... |
| CVE-2014-9958 | — | — | 1.1% | Apr 4, 2018 | An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel... |
| CVE-2014-9957 | — | — | 1.1% | Apr 4, 2018 | An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel... |
| CVE-2014-9956 | — | — | 1.1% | Apr 4, 2018 | An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel... |
| CVE-2014-9955 | — | — | 1.1% | Apr 4, 2018 | An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel... |
| CVE-2014-9954 | — | — | 1.1% | Apr 4, 2018 | An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel... |
| CVE-2014-9953 | — | — | 1.1% | Apr 4, 2018 | An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel... |
| CVE-2014-6604 | — | — | 1.2% | Mar 29, 2018 | Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress ... |
| CVE-2014-5170 | — | — | 4.0% | Mar 29, 2018 | The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveragin... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now