2014 CVE Vulnerabilities

9,002 CVEs published in 2014.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2014-3289Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Applianc...
CVE-2014-3287SQL injection vulnerability in BulkViewFileContentsAction.java in the Java interface in Cisco Unified Communications Man...
CVE-2014-3042IBM CICS Transaction Server 3.1, 3.2, 4.1, 4.2, and 5.1 on z/OS does not properly implement CEMT transactions, which all...
CVE-2014-4012SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecif...
CVE-2014-4011SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspeci...
CVE-2014-4010SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via uns...
CVE-2014-4009SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access ...
CVE-2014-4008SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain acces...
CVE-2014-4007The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access vi...
CVE-2014-4006The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for ...
CVE-2014-4005SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified...
CVE-2014-4004The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, whic...
CVE-2014-4003The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related ...
CVE-2014-3977libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on...
CVE-2014-3048Unspecified vulnerability on the IBM System Storage Virtualization Engine TS7700 allows local users to gain privileges b...
CVE-2014-3038IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypas...
CVE-2014-3036Unspecified vulnerability in IBM API Management 3.0.0.0, when basic authentication is used for APIs, allows remote attac...
CVE-2014-0936IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the c...
CVE-2014-0929Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows ...
CVE-2014-3986include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a...
CVE-2014-3982include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink atta...
CVE-2014-3981acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files...
CVE-2014-0961Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before...
CVE-2014-3291Cisco Wireless LAN Controller (WLC) devices allow remote attackers to cause a denial of service (NULL pointer dereferenc...
CVE-2014-3286The web framework in Cisco WebEx Meeting Server does not properly restrict the content of reply messages, which allows r...

Check if your code is affected by 2014 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now