2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-2252 | — | — | 1.2% | Mar 24, 2014 | Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (de... |
| CVE-2014-2250 | — | — | 3.1% | Mar 24, 2014 | The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient... |
| CVE-2014-0127 | — | — | 1.5% | Mar 24, 2014 | The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle th... |
| CVE-2014-0129 | — | — | 1.7% | Mar 24, 2014 | badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge... |
| CVE-2014-0125 | — | — | 1.9% | Mar 24, 2014 | repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 pla... |
| CVE-2014-0126 | — | — | 1.0% | Mar 24, 2014 | Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x bef... |
| CVE-2014-0124 | — | — | 1.7% | Mar 24, 2014 | The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11... |
| CVE-2014-0123 | — | — | 1.5% | Mar 24, 2014 | The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not pro... |
| CVE-2014-0122 | — | — | 1.0% | Mar 24, 2014 | mod/chat/chat_ajax.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not... |
| CVE-2014-2497 | — | — | 22.3% | Mar 21, 2014 | The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cau... |
| CVE-2014-2276 | — | — | 2.1% | Mar 21, 2014 | The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not prop... |
| CVE-2014-2567 | — | — | 1.0% | Mar 21, 2014 | The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows m... |
| CVE-2014-0879 | — | — | 3.5% | Mar 21, 2014 | Stack-based buffer overflow in the Taskmaster Capture ActiveX control in IBM Datacap Taskmaster Capture 8.0.1, and 8.1 b... |
| CVE-2014-0829 | — | — | 1.4% | Mar 21, 2014 | Multiple buffer overflows in IBM Rational ClearCase 7.x before 7.1.2.13, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0... |
| CVE-2014-0003 | — | — | 7.3% | Mar 21, 2014 | The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remo... |
| CVE-2014-0002 | — | — | 32.5% | Mar 21, 2014 | The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary file... |
| CVE-2014-2124 | — | — | 1.9% | Mar 21, 2014 | Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remot... |
| CVE-2014-2119 | — | — | 2.7% | Mar 21, 2014 | The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7... |
| CVE-2014-0708 | — | — | 1.2% | Mar 21, 2014 | WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows re... |
| CVE-2014-2280 | — | — | 1.9% | Mar 20, 2014 | Cross-site scripting (XSS) vulnerability in the search feature in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allo... |
| CVE-2014-2219 | — | — | 1.2% | Mar 20, 2014 | Cross-site scripting (XSS) vulnerability in whizzywig/wb.php in CMSimple Classic 3.54 and earlier, possibly as downloade... |
| CVE-2014-2077 | — | — | 0.9% | Mar 20, 2014 | Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.... |
| CVE-2014-1904 | — | — | 3.3% | Mar 20, 2014 | Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 b... |
| CVE-2014-1609 | — | — | 3.1% | Mar 20, 2014 | Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL command... |
| CVE-2014-1971 | — | — | 1.2% | Mar 20, 2014 | Cross-site scripting (XSS) vulnerability in Silex before 2.0.0 allows remote attackers to inject arbitrary web script or... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now