2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9594 | — | — | 2.4% | Jan 15, 2015 | Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated us... |
| CVE-2014-9593 | — | — | 3.2% | Jan 15, 2015 | Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts ... |
| CVE-2014-9587 | — | — | 2.1% | Jan 15, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to h... |
| CVE-2014-9570 | — | — | 1.6% | Jan 15, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for... |
| CVE-2014-9561 | — | — | 1.9% | Jan 15, 2015 | Cross-site scripting (XSS) vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to inject a... |
| CVE-2014-9560 | — | — | 2.2% | Jan 15, 2015 | SQL injection vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to execute arbitrary SQL... |
| CVE-2014-9308 | — | — | 51.6% | Jan 15, 2015 | Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor... |
| CVE-2014-8870 | — | — | 1.3% | Jan 15, 2015 | Open redirect vulnerability in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin before 1.1.2 f... |
| CVE-2014-8869 | — | — | 1.2% | Jan 15, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb... |
| CVE-2014-8738 | — | — | 5.2% | Jan 15, 2015 | The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to... |
| CVE-2014-8398 | — | — | 7.1% | Jan 15, 2015 | Multiple untrusted search path vulnerabilities in Corel FastFlick allow local users to execute arbitrary code and conduc... |
| CVE-2014-8397 | — | — | 7.1% | Jan 15, 2015 | Untrusted search path vulnerability in Corel VideoStudio PRO X7 or FastFlick allows local users to execute arbitrary cod... |
| CVE-2014-8396 | — | — | 7.1% | Jan 15, 2015 | Untrusted search path vulnerability in Corel PDF Fusion allows local users to execute arbitrary code and conduct DLL hij... |
| CVE-2014-8395 | — | — | 7.1% | Jan 15, 2015 | Untrusted search path vulnerability in Corel Painter 2015 allows local users to execute arbitrary code and conduct DLL h... |
| CVE-2014-8394 | — | — | 7.1% | Jan 15, 2015 | Multiple untrusted search path vulnerabilities in Corel CAD 2014 allow local users to execute arbitrary code and conduct... |
| CVE-2014-8153 | — | — | 1.9% | Jan 15, 2015 | The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to ... |
| CVE-2014-8151 | — | — | 1.1% | Jan 15, 2015 | The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the Darwi... |
| CVE-2014-8150 | — | — | 6.8% | Jan 15, 2015 | CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers... |
| CVE-2014-7957 | — | — | 1.2% | Jan 15, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote atta... |
| CVE-2014-7956 | — | — | 2.0% | Jan 15, 2015 | Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject a... |
| CVE-2014-7812 | — | — | 1.5% | Jan 15, 2015 | Cross-site scripting (XSS) vulnerability in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allows remote aut... |
| CVE-2014-7811 | — | — | 1.5% | Jan 15, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow ... |
| CVE-2014-0171 | — | — | 2.1% | Jan 15, 2015 | XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualizat... |
| CVE-2014-3314 | — | — | 1.1% | Jan 14, 2015 | Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof auth... |
| CVE-2014-8643 | — | — | 1.5% | Jan 14, 2015 | Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now