2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5859 | — | — | 1.5% | Nov 22, 2015 | The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly recognize the HSTS pr... |
| CVE-2015-5787 | — | — | 1.4% | Nov 22, 2015 | The kernel in Apple iOS before 8.4.1 does not properly restrict debugging features, which allows attackers to bypass bac... |
| CVE-2015-7913 | — | — | 0.4% | Nov 21, 2015 | ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute ar... |
| CVE-2015-7912 | — | — | 3.2% | Nov 21, 2015 | The Ice Faces servlet in ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows ... |
| CVE-2015-7777 | — | — | 1.8% | Nov 21, 2015 | Cross-site scripting (XSS) vulnerability in index.php in JosephErnest Void before 2015-10-02 allows remote attackers to ... |
| CVE-2015-7291 | — | — | 1.0% | Nov 21, 2015 | Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, ... |
| CVE-2015-7290 | — | — | 1.2% | Nov 21, 2015 | Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG8... |
| CVE-2015-7289 | — | — | 2.1% | Nov 21, 2015 | Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded admin... |
| CVE-2015-6376 | — | — | 0.6% | Nov 21, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows rem... |
| CVE-2015-6375 | — | — | 0.3% | Nov 21, 2015 | The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obt... |
| CVE-2015-7773 | — | — | 1.3% | Nov 20, 2015 | Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authe... |
| CVE-2015-7772 | — | — | 1.2% | Nov 20, 2015 | Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for And... |
| CVE-2015-7771 | — | — | 1.2% | Nov 20, 2015 | Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for And... |
| CVE-2015-8087 | — | — | 0.9% | Nov 19, 2015 | Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with so... |
| CVE-2015-8083 | — | — | 1.0% | Nov 19, 2015 | An unspecified module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software befor... |
| CVE-2015-7984 | — | — | 4.1% | Nov 19, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Hor... |
| CVE-2015-7845 | — | — | 0.9% | Nov 19, 2015 | The exception handling mechanism in the CLI Module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified... |
| CVE-2015-7385 | — | — | 2.0% | Nov 19, 2015 | Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject a... |
| CVE-2015-0794 | — | — | 0.3% | Nov 19, 2015 | modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have u... |
| CVE-2015-8236 | — | — | 4.2% | Nov 19, 2015 | Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.... |
| CVE-2015-7910 | — | — | 2.1% | Nov 19, 2015 | Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows re... |
| CVE-2015-4112 | — | — | 1.1% | Nov 19, 2015 | The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elem... |
| CVE-2015-6374 | — | — | 0.8% | Nov 19, 2015 | The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly ... |
| CVE-2015-6371 | — | — | 1.0% | Nov 19, 2015 | Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to re... |
| CVE-2015-6370 | — | — | 0.4% | Nov 19, 2015 | The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices a... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now