2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3289 | — | — | 2.4% | Jun 10, 2014 | Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Applianc... |
| CVE-2014-3287 | — | — | 1.8% | Jun 10, 2014 | SQL injection vulnerability in BulkViewFileContentsAction.java in the Java interface in Cisco Unified Communications Man... |
| CVE-2014-3042 | — | — | 1.4% | Jun 10, 2014 | IBM CICS Transaction Server 3.1, 3.2, 4.1, 4.2, and 5.1 on z/OS does not properly implement CEMT transactions, which all... |
| CVE-2014-4012 | — | — | 1.4% | Jun 9, 2014 | SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecif... |
| CVE-2014-4011 | — | — | 1.4% | Jun 9, 2014 | SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspeci... |
| CVE-2014-4010 | — | — | 1.4% | Jun 9, 2014 | SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via uns... |
| CVE-2014-4009 | — | — | 1.4% | Jun 9, 2014 | SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access ... |
| CVE-2014-4008 | — | — | 1.4% | Jun 9, 2014 | SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain acces... |
| CVE-2014-4007 | — | — | 1.4% | Jun 9, 2014 | The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access vi... |
| CVE-2014-4006 | — | — | 1.4% | Jun 9, 2014 | The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for ... |
| CVE-2014-4005 | — | — | 1.4% | Jun 9, 2014 | SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified... |
| CVE-2014-4004 | — | — | 1.4% | Jun 9, 2014 | The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, whic... |
| CVE-2014-4003 | — | — | 3.0% | Jun 9, 2014 | The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related ... |
| CVE-2014-3977 | — | — | 0.9% | Jun 8, 2014 | libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on... |
| CVE-2014-3048 | — | — | 0.3% | Jun 8, 2014 | Unspecified vulnerability on the IBM System Storage Virtualization Engine TS7700 allows local users to gain privileges b... |
| CVE-2014-3038 | — | — | 0.3% | Jun 8, 2014 | IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypas... |
| CVE-2014-3036 | — | — | 1.3% | Jun 8, 2014 | Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attac... |
| CVE-2014-0936 | — | — | 0.6% | Jun 8, 2014 | IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the c... |
| CVE-2014-0929 | — | — | 0.5% | Jun 8, 2014 | Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows ... |
| CVE-2014-3986 | — | — | 0.3% | Jun 8, 2014 | include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a... |
| CVE-2014-3982 | — | — | 0.3% | Jun 8, 2014 | include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink atta... |
| CVE-2014-3981 | — | — | 0.8% | Jun 8, 2014 | acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files... |
| CVE-2014-0961 | — | — | 0.5% | Jun 8, 2014 | Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before... |
| CVE-2014-3291 | — | — | 1.0% | Jun 8, 2014 | Cisco Wireless LAN Controller (WLC) devices allow remote attackers to cause a denial of service (NULL pointer dereferenc... |
| CVE-2014-3286 | — | — | 1.7% | Jun 8, 2014 | The web framework in Cisco WebEx Meeting Server does not properly restrict the content of reply messages, which allows r... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now