2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2745 | — | — | 3.1% | Apr 11, 2014 | Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers... |
| CVE-2014-2744 | — | — | 3.3% | Apr 11, 2014 | plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compr... |
| CVE-2014-2743 | — | — | 1.9% | Apr 11, 2014 | plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed ... |
| CVE-2014-2742 | — | — | 1.8% | Apr 11, 2014 | Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote att... |
| CVE-2014-2741 | — | — | 3.8% | Apr 11, 2014 | nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of comp... |
| CVE-2014-0920 | — | — | 1.6% | Apr 10, 2014 | IBM SPSS Analytic Server 1.0 before IF002 and 1.0.1 before IF004 logs cleartext passwords, which allows remote authentic... |
| CVE-2014-0908 | — | — | 1.1% | Apr 10, 2014 | The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, an... |
| CVE-2014-2752 | — | — | 1.5% | Apr 10, 2014 | SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote att... |
| CVE-2014-2751 | — | — | 1.5% | Apr 10, 2014 | SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access v... |
| CVE-2014-2750 | — | — | — | Apr 10, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2744, CVE-2014-2745. Reason: This candidate is... |
| CVE-2014-2749 | — | — | 1.5% | Apr 10, 2014 | The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and... |
| CVE-2014-2748 | — | — | 1.5% | Apr 10, 2014 | The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or ... |
| CVE-2014-2708 | — | — | 2.0% | Apr 10, 2014 | Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to... |
| CVE-2014-2583 | — | — | 4.1% | Apr 10, 2014 | Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.... |
| CVE-2014-1455 | — | — | 1.3% | Apr 10, 2014 | SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, p... |
| CVE-2014-0331 | — | — | 1.9% | Apr 10, 2014 | Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allo... |
| CVE-2014-2141 | — | — | 1.4% | Apr 10, 2014 | The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initial... |
| CVE-2014-2129 | — | — | 1.7% | Apr 10, 2014 | The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5),... |
| CVE-2014-2128 | — | — | 1.9% | Apr 10, 2014 | The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40)... |
| CVE-2014-2127 | — | — | 11.5% | Apr 10, 2014 | Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 be... |
| CVE-2014-2126 | — | — | 2.1% | Apr 10, 2014 | Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 be... |
| CVE-2014-2544 | — | — | 3.0% | Apr 10, 2014 | Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in ... |
| CVE-2014-0166 | — | — | 8.9% | Apr 10, 2014 | The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does ... |
| CVE-2014-0165 | — | — | 2.4% | Apr 10, 2014 | WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contr... |
| CVE-2014-1729 | — | — | 1.4% | Apr 9, 2014 | Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allo... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now