2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-5127Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect u...
CVE-2014-4930Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 buil...
CVE-2014-2593The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary co...
CVE-2014-3351Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a proble...
CVE-2014-3350Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allow...
CVE-2014-3349Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file...
CVE-2014-3346The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software)...
CVE-2014-3093IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the...
CVE-2014-3084IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5....
CVE-2014-3024Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5....
CVE-2014-0897The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak...
CVE-2014-0888IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authentic...
CVE-2014-0600FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or w...
CVE-2014-3347Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to...
CVE-2014-3345The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software)...
CVE-2014-4200vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 per...
CVE-2014-4199vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local ...
CVE-2014-5399SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows ...
CVE-2014-5398Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitr...
CVE-2014-5397Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 throug...
CVE-2014-4619EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P0...
CVE-2014-3344Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home ...
CVE-2014-2381Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows loc...
CVE-2014-2380Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows rem...
CVE-2014-0762The CG Automation Software DNP3 driver, used in the ePAQ-9410 Substation Gateway products, does not validate input corr...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now