2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-3866 | — | — | 1.1% | May 26, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remo... |
| CVE-2014-0878 | — | — | 2.1% | May 26, 2014 | The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Editi... |
| CVE-2014-0893 | — | — | 1.1% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006... |
| CVE-2014-0849 | — | — | 1.1% | May 26, 2014 | IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before... |
| CVE-2014-0825 | — | — | 0.9% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in openreport.jsp in IBM Maximo Asset Management 7.x before 7.1.1.12 IFIX.20140... |
| CVE-2014-0824 | — | — | 0.9% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.8 LAFIX.20140319-0839 and 7.1.1... |
| CVE-2014-3867 | — | — | 2.0% | May 26, 2014 | The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a S... |
| CVE-2014-3014 | — | — | 1.4% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0... |
| CVE-2014-0906 | — | — | 1.4% | May 26, 2014 | The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not check whether a session cookie i... |
| CVE-2014-3261 | — | — | 1.8% | May 26, 2014 | Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing ... |
| CVE-2014-3015 | — | — | 0.6% | May 26, 2014 | Cross-site request forgery (CSRF) vulnerability in the Web player in IBM Sametime Proxy Server and Web Client 9.0 throug... |
| CVE-2014-2607 | — | — | 3.4% | May 26, 2014 | Unspecified vulnerability in HP Operations Manager i 9.1 through 9.13 and 9.2 through 9.24 allows remote authenticated u... |
| CVE-2014-2201 | — | — | 1.9% | May 26, 2014 | The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 ... |
| CVE-2014-2200 | — | — | 1.4% | May 26, 2014 | Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows rem... |
| CVE-2014-3276 | — | — | 2.2% | May 26, 2014 | Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during rec... |
| CVE-2014-3275 | — | — | 1.6% | May 26, 2014 | SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier all... |
| CVE-2014-3274 | — | — | 1.1% | May 26, 2014 | Cisco TelePresence System (CTS) 6.0(.5)(5) and earlier falls back to HTTP when certain HTTPS sessions cannot be establis... |
| CVE-2014-3272 | — | — | 0.3% | May 26, 2014 | The Agent in Cisco Tidal Enterprise Scheduler (TES) 6.1 and earlier allows local users to gain privileges via crafted Ti... |
| CVE-2014-3267 | — | — | 1.2% | May 26, 2014 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows re... |
| CVE-2014-3266 | — | — | 1.2% | May 26, 2014 | Cross-site scripting (XSS) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote at... |
| CVE-2014-2504 | — | — | 3.0% | May 26, 2014 | EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote a... |
| CVE-2014-2196 | — | — | 2.4% | May 26, 2014 | Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allow... |
| CVE-2014-3284 | — | — | 1.2% | May 25, 2014 | Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service... |
| CVE-2014-0943 | — | — | 2.3% | May 25, 2014 | IBM WebSphere Commerce 6.0 Feature Pack 2 through Feature Pack 5, 7.0.0.0 through 7.0.0.8, and 7.0 Feature Pack 1 throug... |
| CVE-2014-0639 | — | — | 1.2% | May 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer 5.x before GRC 5.4 SP1 P3 allow remote attackers t... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now