2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-6122IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8....
CVE-2014-6121Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix...
CVE-2014-6119IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8....
CVE-2014-8992Cross-site scripting (XSS) vulnerability in manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution 2.3.2-pl a...
CVE-2014-8018Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application S...
CVE-2014-8017The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryptio...
CVE-2014-8015The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbi...
CVE-2014-5208BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00...
CVE-2014-8899Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for...
CVE-2014-8898Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for...
CVE-2014-8897Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for...
CVE-2014-8896The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through ...
CVE-2014-7286Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local us...
CVE-2014-8142Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.3...
CVE-2014-9296The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentic...
CVE-2014-9295Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a...
CVE-2014-9294util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers...
CVE-2014-9293The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key,...
CVE-2014-9193Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root priv...
CVE-2014-8019Directory traversal vulnerability in Cisco Enterprise Content Delivery System (ECDS) allows remote attackers to read arb...
CVE-2014-8007Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML so...
CVE-2014-3410The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain an...
CVE-2014-5213nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allo...
CVE-2014-5212Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allo...
CVE-2014-9408Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activat...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now