2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6481 | — | — | 1.7% | Dec 21, 2015 | The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root passwor... |
| CVE-2015-6480 | — | — | 1.8% | Dec 21, 2015 | The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows... |
| CVE-2015-5001 | — | — | 2.1% | Dec 21, 2015 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.... |
| CVE-2015-4998 | — | — | 1.4% | Dec 21, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27,... |
| CVE-2015-4993 | — | — | 1.4% | Dec 21, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27,... |
| CVE-2015-1836 | — | — | 7.4% | Dec 21, 2015 | Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.... |
| CVE-2015-1772 | — | — | 6.8% | Dec 21, 2015 | The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere Big... |
| CVE-2015-6934 | — | — | 5.0% | Dec 21, 2015 | Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCe... |
| CVE-2015-7756 | — | — | 2.4% | Dec 19, 2015 | The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before ... |
| CVE-2015-7755 | CRITICAL | 9.8 | 61.4% | Dec 19, 2015 | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r... |
| CVE-2015-6429 | — | — | 1.7% | Dec 19, 2015 | The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a d... |
| CVE-2015-6556 | — | — | 0.3% | Dec 18, 2015 | EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows ... |
| CVE-2015-6428 | — | — | 2.4% | Dec 18, 2015 | Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP reques... |
| CVE-2015-6427 | — | — | 1.7% | Dec 18, 2015 | Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggeri... |
| CVE-2015-6426 | — | — | 0.4% | Dec 18, 2015 | Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitr... |
| CVE-2015-6424 | — | — | 0.4% | Dec 18, 2015 | The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass i... |
| CVE-2015-8602 | — | — | 0.9% | Dec 17, 2015 | The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remot... |
| CVE-2015-8601 | — | — | 1.2% | Dec 17, 2015 | The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket f... |
| CVE-2015-8600 | — | — | 1.4% | Dec 17, 2015 | The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive... |
| CVE-2015-8369 | — | — | 2.3% | Dec 17, 2015 | SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execu... |
| CVE-2015-8368 | — | — | 5.4% | Dec 17, 2015 | ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u... |
| CVE-2015-8341 | — | — | 2.0% | Dec 17, 2015 | The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and i... |
| CVE-2015-8340 | — | — | 0.4% | Dec 17, 2015 | The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly release locks, which might ... |
| CVE-2015-8339 | — | — | 0.4% | Dec 17, 2015 | The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain... |
| CVE-2015-8338 | — | — | 0.4% | Dec 17, 2015 | Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2)... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now