2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-5127 | — | — | 2.1% | Aug 29, 2014 | Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect u... |
| CVE-2014-4930 | — | — | 3.6% | Aug 29, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 buil... |
| CVE-2014-2593 | — | — | 1.5% | Aug 29, 2014 | The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary co... |
| CVE-2014-3351 | — | — | 2.9% | Aug 29, 2014 | Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a proble... |
| CVE-2014-3350 | — | — | 1.6% | Aug 29, 2014 | Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allow... |
| CVE-2014-3349 | — | — | 1.6% | Aug 29, 2014 | Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file... |
| CVE-2014-3346 | — | — | 1.9% | Aug 29, 2014 | The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software)... |
| CVE-2014-3093 | — | — | 0.3% | Aug 29, 2014 | IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the... |
| CVE-2014-3084 | — | — | 1.7% | Aug 29, 2014 | IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5.... |
| CVE-2014-3024 | — | — | 0.8% | Aug 29, 2014 | Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.... |
| CVE-2014-0897 | — | — | 0.6% | Aug 29, 2014 | The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak... |
| CVE-2014-0888 | — | — | 1.0% | Aug 29, 2014 | IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authentic... |
| CVE-2014-0600 | — | — | 3.1% | Aug 29, 2014 | FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or w... |
| CVE-2014-3347 | — | — | 1.0% | Aug 28, 2014 | Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to... |
| CVE-2014-3345 | — | — | 2.2% | Aug 28, 2014 | The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software)... |
| CVE-2014-4200 | — | — | 0.4% | Aug 28, 2014 | vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 per... |
| CVE-2014-4199 | — | — | 0.4% | Aug 28, 2014 | vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local ... |
| CVE-2014-5399 | — | — | 1.6% | Aug 28, 2014 | SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows ... |
| CVE-2014-5398 | — | — | 0.6% | Aug 28, 2014 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitr... |
| CVE-2014-5397 | — | — | 1.5% | Aug 28, 2014 | Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 throug... |
| CVE-2014-4619 | — | — | 4.4% | Aug 28, 2014 | EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P0... |
| CVE-2014-3344 | — | — | 2.0% | Aug 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home ... |
| CVE-2014-2381 | — | — | 0.1% | Aug 28, 2014 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows loc... |
| CVE-2014-2380 | — | — | 0.8% | Aug 28, 2014 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows rem... |
| CVE-2014-0762 | — | — | 0.3% | Aug 28, 2014 | The CG Automation Software DNP3 driver, used in the ePAQ-9410 Substation Gateway products, does not validate input corr... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now