2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9269 | — | — | 3.2% | Oct 1, 2018 | The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress a... |
| CVE-2015-8298 | — | — | 3.5% | Sep 24, 2018 | Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to exe... |
| CVE-2015-9265 | — | — | — | Aug 30, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14622. Reason: This candidate is a reservation... |
| CVE-2015-9264 | — | — | 1.9% | Aug 27, 2018 | Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation... |
| CVE-2015-9263 | — | — | 11.9% | Aug 27, 2018 | An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows ... |
| CVE-2015-5243 | — | — | 6.2% | Aug 20, 2018 | phpWhois allows remote attackers to execute arbitrary code via a crafted whois record. |
| CVE-2015-5160 | — | — | 0.4% | Aug 20, 2018 | libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which all... |
| CVE-2015-9262 | — | — | 5.9% | Aug 1, 2018 | _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or pot... |
| CVE-2015-4968 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-1991 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-1990 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-0163 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-0155 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-0154 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-0230 | — | — | — | Jul 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-4043 | — | — | 1.3% | Jun 19, 2018 | SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2015-4664 | — | — | 20.8% | Jun 18, 2018 | An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers t... |
| CVE-2015-9238 | — | — | 1.5% | May 31, 2018 | secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first ar... |
| CVE-2015-9236 | — | — | 1.5% | May 31, 2018 | Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsist... |
| CVE-2015-7610 | — | — | 1.2% | May 30, 2018 | Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 P... |
| CVE-2015-9243 | — | — | 1.0% | May 29, 2018 | When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined an... |
| CVE-2015-9242 | — | — | 2.1% | May 29, 2018 | Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to ra... |
| CVE-2015-9241 | — | — | 2.1% | May 29, 2018 | Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be ... |
| CVE-2015-9240 | — | — | 0.9% | May 29, 2018 | Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addres... |
| CVE-2015-9235 | — | — | 8.7% | May 29, 2018 | In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally si... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now