2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6122 | — | — | 1.5% | Dec 23, 2014 | IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.... |
| CVE-2014-6121 | — | — | 0.9% | Dec 23, 2014 | Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix... |
| CVE-2014-6119 | — | — | 3.6% | Dec 23, 2014 | IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.... |
| CVE-2014-8992 | — | — | 1.4% | Dec 22, 2014 | Cross-site scripting (XSS) vulnerability in manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution 2.3.2-pl a... |
| CVE-2014-8018 | — | — | 1.8% | Dec 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application S... |
| CVE-2014-8017 | — | — | 1.2% | Dec 22, 2014 | The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryptio... |
| CVE-2014-8015 | — | — | 1.2% | Dec 22, 2014 | The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbi... |
| CVE-2014-5208 | — | — | 23.1% | Dec 22, 2014 | BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00... |
| CVE-2014-8899 | — | — | 0.8% | Dec 22, 2014 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for... |
| CVE-2014-8898 | — | — | 0.8% | Dec 22, 2014 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for... |
| CVE-2014-8897 | — | — | 0.8% | Dec 22, 2014 | Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for... |
| CVE-2014-8896 | — | — | 0.8% | Dec 22, 2014 | The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through ... |
| CVE-2014-7286 | — | — | 1.2% | Dec 22, 2014 | Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local us... |
| CVE-2014-8142 | — | — | 53.2% | Dec 20, 2014 | Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.3... |
| CVE-2014-9296 | — | — | 16.2% | Dec 20, 2014 | The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentic... |
| CVE-2014-9295 | — | — | 78.1% | Dec 20, 2014 | Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a... |
| CVE-2014-9294 | — | — | 13.0% | Dec 20, 2014 | util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers... |
| CVE-2014-9293 | — | — | 13.0% | Dec 20, 2014 | The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key,... |
| CVE-2014-9193 | — | — | 3.1% | Dec 20, 2014 | Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root priv... |
| CVE-2014-8019 | — | — | 2.9% | Dec 20, 2014 | Directory traversal vulnerability in Cisco Enterprise Content Delivery System (ECDS) allows remote attackers to read arb... |
| CVE-2014-8007 | — | — | 1.3% | Dec 20, 2014 | Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML so... |
| CVE-2014-3410 | — | — | 1.1% | Dec 20, 2014 | The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain an... |
| CVE-2014-5213 | — | — | 2.0% | Dec 19, 2014 | nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allo... |
| CVE-2014-5212 | — | — | 2.0% | Dec 19, 2014 | Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allo... |
| CVE-2014-9408 | — | — | 2.2% | Dec 19, 2014 | Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activat... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now