2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9342 | — | — | 2.1% | Dec 8, 2014 | Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in... |
| CVE-2014-9219 | — | — | 1.2% | Dec 8, 2014 | Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allow... |
| CVE-2014-9218 | — | — | 11.1% | Dec 8, 2014 | libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows re... |
| CVE-2014-9217 | — | — | 2.3% | Dec 8, 2014 | Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards. |
| CVE-2014-8600 | — | — | 2.1% | Dec 8, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, an... |
| CVE-2014-8371 | — | — | 0.6% | Dec 8, 2014 | VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not prope... |
| CVE-2014-4880 | — | — | 72.1% | Dec 8, 2014 | Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta... |
| CVE-2014-4631 | — | — | 1.7% | Dec 8, 2014 | RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or u... |
| CVE-2014-3797 | — | — | 1.8% | Dec 8, 2014 | Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote att... |
| CVE-2014-3616 | — | — | 5.7% | Dec 8, 2014 | nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, ... |
| CVE-2014-1693 | — | — | 2.2% | Dec 8, 2014 | Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inje... |
| CVE-2014-9304 | — | — | 8.1% | Dec 7, 2014 | Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and e... |
| CVE-2014-9303 | — | — | 3.3% | Dec 7, 2014 | EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator ... |
| CVE-2014-9302 | — | — | 2.0% | Dec 7, 2014 | Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Servi... |
| CVE-2014-9301 | — | — | 4.0% | Dec 7, 2014 | Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows ... |
| CVE-2014-9300 | — | — | 0.6% | Dec 7, 2014 | Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Servic... |
| CVE-2014-8868 | — | — | 7.0% | Dec 7, 2014 | EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain ... |
| CVE-2014-9117 | — | — | 2.3% | Dec 6, 2014 | MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attacke... |
| CVE-2014-8651 | — | — | 0.4% | Dec 6, 2014 | The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to... |
| CVE-2014-9278 | — | — | 1.8% | Dec 6, 2014 | The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows ... |
| CVE-2014-7251 | — | — | 0.3% | Dec 6, 2014 | XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP... |
| CVE-2014-6140 | — | — | 6.5% | Dec 6, 2014 | IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across diffe... |
| CVE-2014-5429 | — | — | 1.4% | Dec 6, 2014 | DNP Master Driver 3.02 and earlier in Elipse SCADA 2.29 build 141 and earlier, E3 1.0 through 4.6, and Elipse Power 1.0 ... |
| CVE-2014-4629 | — | — | 3.3% | Dec 6, 2014 | EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read ... |
| CVE-2014-3099 | — | — | 0.4% | Dec 6, 2014 | Unspecified vulnerability in the Security component in IBM Systems Director 6.3.0 through 6.3.5 allows local users to ob... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now