2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7428 | — | — | 1.0% | Feb 29, 2016 | Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remot... |
| CVE-2015-7262 | — | — | 1.5% | Feb 27, 2016 | QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated user... |
| CVE-2015-7261 | — | — | 1.6% | Feb 27, 2016 | The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded... |
| CVE-2015-6036 | — | — | 1.7% | Feb 27, 2016 | QNAP Signage Station before 2.0.1 allows remote attackers to bypass authentication, and consequently upload files, via a... |
| CVE-2015-6022 | — | — | 3.1% | Feb 27, 2016 | Unrestricted file upload vulnerability in QNAP Signage Station before 2.0.1 allows remote authenticated users to execute... |
| CVE-2015-3591 | — | — | — | Feb 25, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3591. Reason: This candidate is a duplicate of... |
| CVE-2015-5351 | — | — | 9.2% | Feb 25, 2016 | The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before ... |
| CVE-2015-5346 | — | — | 10.6% | Feb 25, 2016 | Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when diff... |
| CVE-2015-5345 | — | — | 18.4% | Feb 25, 2016 | The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 p... |
| CVE-2015-5174 | — | — | 12.6% | Feb 25, 2016 | Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x bef... |
| CVE-2015-8277 | — | — | 28.7% | Feb 24, 2016 | Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Upda... |
| CVE-2015-8805 | — | — | 2.7% | Feb 23, 2016 | The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces inco... |
| CVE-2015-8804 | — | — | 3.9% | Feb 23, 2016 | x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in... |
| CVE-2015-8803 | — | — | 4.1% | Feb 23, 2016 | The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces inco... |
| CVE-2015-5294 | — | — | — | Feb 23, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-5342 | — | — | 1.3% | Feb 22, 2016 | The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remot... |
| CVE-2015-5341 | — | — | 1.3% | Feb 22, 2016 | mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availabil... |
| CVE-2015-5340 | — | — | 1.3% | Feb 22, 2016 | Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badg... |
| CVE-2015-5339 | — | — | 1.3% | Feb 22, 2016 | The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.... |
| CVE-2015-5338 | — | — | 0.8% | Feb 22, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2... |
| CVE-2015-5337 | — | — | 1.1% | Feb 22, 2016 | Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the av... |
| CVE-2015-5336 | — | — | 0.9% | Feb 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, ... |
| CVE-2015-5335 | — | — | 0.7% | Feb 22, 2016 | Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x befor... |
| CVE-2015-5332 | — | — | 1.7% | Feb 22, 2016 | Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk cons... |
| CVE-2015-5331 | — | — | 1.3% | Feb 22, 2016 | Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now