2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7447 | — | — | 1.9% | Dec 31, 2015 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.... |
| CVE-2015-7284 | — | — | 1.1% | Dec 31, 2015 | Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote att... |
| CVE-2015-7283 | — | — | 3.7% | Dec 31, 2015 | The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 f... |
| CVE-2015-7282 | — | — | 1.0% | Dec 31, 2015 | ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it eas... |
| CVE-2015-7281 | — | — | 0.6% | Dec 31, 2015 | Cross-site request forgery (CSRF) vulnerability on ReadyNet WRT300N-DD devices with firmware 1.0.26 allows remote attack... |
| CVE-2015-7280 | — | — | 2.4% | Dec 31, 2015 | The web administration interface on ReadyNet WRT300N-DD devices with firmware 1.0.26 has a default password of admin for... |
| CVE-2015-7279 | — | — | 1.0% | Dec 31, 2015 | Amped Wireless R10000 devices with firmware 2.5.2.11 use an improper algorithm for selecting the ID value in the header ... |
| CVE-2015-7278 | — | — | 0.6% | Dec 31, 2015 | Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote at... |
| CVE-2015-7277 | — | — | 2.4% | Dec 31, 2015 | The web administration interface on Amped Wireless R10000 devices with firmware 2.5.2.11 has a default password of admin... |
| CVE-2015-6020 | — | — | 2.2% | Dec 31, 2015 | ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privilege... |
| CVE-2015-6019 | — | — | 3.0% | Dec 31, 2015 | The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout ... |
| CVE-2015-6018 | — | — | 20.6% | Dec 31, 2015 | The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attac... |
| CVE-2015-6017 | — | — | 2.1% | Dec 31, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware ... |
| CVE-2015-6016 | — | — | 5.7% | Dec 31, 2015 | ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N... |
| CVE-2015-5996 | — | — | 1.4% | Dec 31, 2015 | Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo... |
| CVE-2015-5995 | — | — | 19.1% | Dec 31, 2015 | Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke... |
| CVE-2015-5994 | — | — | 1.3% | Dec 31, 2015 | The web management interface on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 has a default password ... |
| CVE-2015-2918 | — | — | 0.8% | Dec 31, 2015 | The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restric... |
| CVE-2015-2913 | — | — | 1.9% | Dec 31, 2015 | server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition befor... |
| CVE-2015-2912 | — | — | 1.3% | Dec 31, 2015 | The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 doe... |
| CVE-2015-2896 | — | — | 1.2% | Dec 31, 2015 | The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sens... |
| CVE-2015-2895 | — | — | 1.9% | Dec 31, 2015 | Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute... |
| CVE-2015-2894 | — | — | 1.4% | Dec 31, 2015 | Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attac... |
| CVE-2015-2876 | — | — | 2.8% | Dec 31, 2015 | Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Pl... |
| CVE-2015-2875 | — | — | 3.2% | Dec 31, 2015 | Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plu... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now