2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-5073vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands ...
CVE-2014-2390Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) b...
CVE-2014-5337The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected post...
CVE-2014-5128Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attacker...
CVE-2014-5127Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect u...
CVE-2014-4930Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 buil...
CVE-2014-2593The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary co...
CVE-2014-4806MEDIUM5.5The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, ...
CVE-2014-3351Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a proble...
CVE-2014-3350Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allow...
CVE-2014-3349Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file...
CVE-2014-3346The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software)...
CVE-2014-3093IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the...
CVE-2014-3084IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5....
CVE-2014-3024Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5....
CVE-2014-0897The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak...
CVE-2014-0888IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authentic...
CVE-2014-0600FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or w...
CVE-2014-3347Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to...
CVE-2014-3345The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software)...
CVE-2014-4200vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 per...
CVE-2014-4199vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local ...
CVE-2014-5399SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows ...
CVE-2014-5398Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitr...
CVE-2014-5397Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 throug...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now