2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

CVE IDSeverityCVSSDescription
CVE-2014-2631Unspecified vulnerability in HP Application Lifecycle Management (aka Quality Center) 11.5x and 12.0x allows local users...
CVE-2014-2628Unspecified vulnerability in HP Enterprise Maps 1 allows remote authenticated users to obtain sensitive information via ...
CVE-2014-3330Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, w...
CVE-2014-3327The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE bef...
CVE-2014-3076IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information...
CVE-2014-2357The GPT library in the Telegyr 8979 Master Protocol application in SUBNET SubSTATION Server 2 before SSNET 2.12 HF18808 ...
CVE-2014-3336SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticate...
CVE-2014-3333The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by ...
CVE-2014-3332Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions setting, which allows re...
CVE-2014-5195Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switchin...
CVE-2014-5194Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbi...
CVE-2014-5193Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary...
CVE-2014-5192SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL command...
CVE-2014-5191Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to injec...
CVE-2014-5190Cross-site scripting (XSS) vulnerability in captcha-secureimage/test/index.php in the SI CAPTCHA Anti-Spam plugin 2.7.4 ...
CVE-2014-5189SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers...
CVE-2014-5188Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote attackers ...
CVE-2014-4647Stack-based buffer overflow in the loadExtensionFactory method in the TSVisualization ActiveX control in Embarcadero ER/...
CVE-2014-3914Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows ...
CVE-2014-3855Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a ....
CVE-2014-3854Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack ...
CVE-2014-3853Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attack...
CVE-2014-3852Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remo...
CVE-2014-3851usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local ...
CVE-2014-3800XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names ...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now