2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8369 | — | — | 2.3% | Dec 17, 2015 | SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execu... |
| CVE-2015-8368 | — | — | 5.4% | Dec 17, 2015 | ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u... |
| CVE-2015-8341 | — | — | 2.0% | Dec 17, 2015 | The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and i... |
| CVE-2015-8340 | — | — | 0.4% | Dec 17, 2015 | The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly release locks, which might ... |
| CVE-2015-8339 | — | — | 0.4% | Dec 17, 2015 | The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain... |
| CVE-2015-8338 | — | — | 0.4% | Dec 17, 2015 | Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2)... |
| CVE-2015-8327 | — | — | 10.2% | Dec 17, 2015 | Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters... |
| CVE-2015-7527 | — | — | 5.2% | Dec 17, 2015 | lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via sh... |
| CVE-2015-7518 | — | — | 1.8% | Dec 17, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attacker... |
| CVE-2015-5277 | — | — | 0.6% | Dec 17, 2015 | The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6... |
| CVE-2015-5204 | — | — | 3.4% | Dec 17, 2015 | CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android befor... |
| CVE-2015-4027 | — | — | 1.2% | Dec 17, 2015 | The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t... |
| CVE-2015-8581 | — | — | — | Dec 16, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0779. Reason: This candidate is a duplicate of C... |
| CVE-2015-8580 | — | — | 3.7% | Dec 16, 2015 | Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Reader before 7.2.2... |
| CVE-2015-8566 | — | — | 8.9% | Dec 16, 2015 | The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspeci... |
| CVE-2015-8565 | — | — | 2.6% | Dec 16, 2015 | Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have ... |
| CVE-2015-8564 | — | — | 2.6% | Dec 16, 2015 | Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via d... |
| CVE-2015-8563 | — | — | 0.8% | Dec 16, 2015 | Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x ... |
| CVE-2015-8562 | — | — | 98.3% | Dec 16, 2015 | Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi... |
| CVE-2015-8476 | — | — | 2.0% | Dec 16, 2015 | Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via... |
| CVE-2015-8358 | — | — | 7.0% | Dec 16, 2015 | Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t... |
| CVE-2015-8357 | — | — | 8.8% | Dec 16, 2015 | Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t... |
| CVE-2015-5304 | — | — | 1.8% | Dec 16, 2015 | Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the ser... |
| CVE-2015-8579 | — | — | 1.5% | Dec 16, 2015 | Kaspersky Total Security 2015 15.0.2.361 allocates memory with Read, Write, Execute (RWX) permissions at predictable add... |
| CVE-2015-8578 | — | — | 1.4% | Dec 16, 2015 | AVG Internet Security 2015 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when pr... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now