2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3329 | — | — | 2.2% | Jul 29, 2014 | Cross-site scripting (XSS) vulnerability in the web-server component in Cisco Prime Data Center Network Manager (DCNM) 6... |
| CVE-2014-3057 | — | — | 1.8% | Jul 29, 2014 | Cross-site scripting (XSS) vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x thr... |
| CVE-2014-3056 | — | — | 2.1% | Jul 29, 2014 | The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to... |
| CVE-2014-3055 | — | — | 1.9% | Jul 29, 2014 | SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 ... |
| CVE-2014-3054 | — | — | 1.8% | Jul 29, 2014 | Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x throu... |
| CVE-2014-3050 | — | — | 0.9% | Jul 29, 2014 | IBM Rational Team Concert (RTC) 3.x before 3.0.1.6 IF3 and 4.x before 4.0.7 does not properly integrate with build engin... |
| CVE-2014-3026 | — | — | 1.0% | Jul 29, 2014 | CRLF injection vulnerability in IBM Maximo Asset Management 7.5 through 7.5.0.6, and 7.5 through 7.5.0.3 and 7.5.1 throu... |
| CVE-2014-3020 | — | — | 0.3% | Jul 29, 2014 | install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1... |
| CVE-2014-0889 | — | — | 1.2% | Jul 29, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDisco... |
| CVE-2014-5116 | — | — | 7.8% | Jul 29, 2014 | The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attac... |
| CVE-2014-5115 | — | — | 6.3% | Jul 29, 2014 | Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname ... |
| CVE-2014-5114 | — | — | 2.1% | Jul 29, 2014 | WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter. |
| CVE-2014-5031 | — | — | 2.9% | Jul 29, 2014 | The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote atta... |
| CVE-2014-5030 | — | — | 0.4% | Jul 29, 2014 | CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) ... |
| CVE-2014-5029 | — | — | 0.3% | Jul 29, 2014 | The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a fil... |
| CVE-2014-4909 | — | — | 5.4% | Jul 29, 2014 | Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote ... |
| CVE-2014-4710 | — | — | 3.2% | Jul 29, 2014 | Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbit... |
| CVE-2014-2226 | — | — | 1.5% | Jul 29, 2014 | Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the... |
| CVE-2014-0475 | — | — | 2.7% | Jul 29, 2014 | Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent a... |
| CVE-2014-0103 | — | — | 0.4% | Jul 29, 2014 | WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users... |
| CVE-2014-3553 | — | — | 1.0% | Jul 29, 2014 | mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, a... |
| CVE-2014-3552 | — | — | 1.2% | Jul 29, 2014 | The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5... |
| CVE-2014-3551 | — | — | 1.7% | Jul 29, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4... |
| CVE-2014-3550 | — | — | 1.2% | Jul 29, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 a... |
| CVE-2014-3549 | — | — | 1.2% | Jul 29, 2014 | Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in M... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now