2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2874 | — | — | 4.2% | Dec 31, 2015 | Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices ... |
| CVE-2015-8703 | — | — | 4.9% | Dec 30, 2015 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authe... |
| CVE-2015-7794 | — | — | 1.6% | Dec 30, 2015 | Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traf... |
| CVE-2015-7793 | — | — | 1.6% | Dec 30, 2015 | Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traf... |
| CVE-2015-7792 | — | — | 2.8% | Dec 30, 2015 | Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors. |
| CVE-2015-7790 | — | — | 1.0% | Dec 30, 2015 | Cross-site scripting (XSS) vulnerability on ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allows remote att... |
| CVE-2015-7789 | — | — | 0.6% | Dec 30, 2015 | ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspe... |
| CVE-2015-7788 | — | — | 2.2% | Dec 30, 2015 | ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to execute arbitrary commands via unsp... |
| CVE-2015-7787 | — | — | 0.6% | Dec 30, 2015 | ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to discover the WPA2-PSK passphrase vi... |
| CVE-2015-7784 | — | — | 1.1% | Dec 30, 2015 | SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl pl... |
| CVE-2015-7782 | — | — | 0.8% | Dec 30, 2015 | Cross-site scripting (XSS) vulnerability in Let's PHP! Frame high-speed chat before 2015-09-22 allows remote attackers t... |
| CVE-2015-7252 | — | — | 2.7% | Dec 30, 2015 | Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_... |
| CVE-2015-7251 | — | — | 10.6% | Dec 30, 2015 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, whic... |
| CVE-2015-7250 | — | — | 15.5% | Dec 30, 2015 | Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE ... |
| CVE-2015-7249 | — | — | 5.5% | Dec 30, 2015 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access r... |
| CVE-2015-7248 | — | — | 6.9% | Dec 30, 2015 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password ha... |
| CVE-2015-5663 | — | — | 0.9% | Dec 30, 2015 | The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse f... |
| CVE-2015-8467 | HIGH | 7.5 | 3.1% | Dec 29, 2015 | The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x ... |
| CVE-2015-7791 | — | — | 1.6% | Dec 29, 2015 | Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote... |
| CVE-2015-7540 | HIGH | 7.5 | 7.1% | Dec 29, 2015 | The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful... |
| CVE-2015-5330 | — | — | 6.1% | Dec 29, 2015 | ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3,... |
| CVE-2015-5299 | MEDIUM | 5.3 | 13.3% | Dec 29, 2015 | The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x b... |
| CVE-2015-5296 | MEDIUM | 5.4 | 7.3% | Dec 29, 2015 | Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but ... |
| CVE-2015-5252 | HIGH | 7.2 | 13.3% | Dec 29, 2015 | vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with cert... |
| CVE-2015-3223 | — | — | 6.8% | Dec 29, 2015 | The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now