2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0218 | — | — | 1.8% | May 27, 2014 | Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.... |
| CVE-2014-0217 | — | — | 1.9% | May 27, 2014 | enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before li... |
| CVE-2014-0216 | — | — | 2.1% | May 27, 2014 | The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x ... |
| CVE-2014-0215 | — | — | 1.7% | May 27, 2014 | The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6... |
| CVE-2014-0214 | — | — | 3.0% | May 27, 2014 | login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a Mood... |
| CVE-2014-0213 | — | — | 1.0% | May 27, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moo... |
| CVE-2014-3866 | — | — | 1.1% | May 26, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remo... |
| CVE-2014-0878 | — | — | 2.1% | May 26, 2014 | The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Editi... |
| CVE-2014-0893 | — | — | 1.1% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006... |
| CVE-2014-0849 | — | — | 1.1% | May 26, 2014 | IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before... |
| CVE-2014-0825 | — | — | 0.9% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in openreport.jsp in IBM Maximo Asset Management 7.x before 7.1.1.12 IFIX.20140... |
| CVE-2014-0824 | — | — | 0.9% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.8 LAFIX.20140319-0839 and 7.1.1... |
| CVE-2014-3867 | — | — | 2.0% | May 26, 2014 | The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a S... |
| CVE-2014-3014 | — | — | 1.4% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0... |
| CVE-2014-0906 | — | — | 1.4% | May 26, 2014 | The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie i... |
| CVE-2014-3261 | — | — | 1.8% | May 26, 2014 | Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing ... |
| CVE-2014-3015 | — | — | 0.6% | May 26, 2014 | Cross-site request forgery (CSRF) vulnerability in the Web player in IBM Sametime Proxy Server and Web Client 9.0 throug... |
| CVE-2014-2607 | — | — | 3.4% | May 26, 2014 | Unspecified vulnerability in HP Operations Manager i 9.1 through 9.13 and 9.2 through 9.24 allows remote authenticated u... |
| CVE-2014-2201 | — | — | 1.9% | May 26, 2014 | The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 ... |
| CVE-2014-2200 | — | — | 1.4% | May 26, 2014 | Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows rem... |
| CVE-2014-3276 | — | — | 2.2% | May 26, 2014 | Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during rec... |
| CVE-2014-3275 | — | — | 1.6% | May 26, 2014 | SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier all... |
| CVE-2014-3274 | — | — | 1.1% | May 26, 2014 | Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be establis... |
| CVE-2014-3272 | — | — | 0.3% | May 26, 2014 | The Agent in Cisco Tidal Enterprise Scheduler (TES) 6.1 and earlier allows local users to gain privileges via crafted Ti... |
| CVE-2014-3267 | — | — | 1.2% | May 26, 2014 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows re... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now