2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-6481The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root passwor...
CVE-2015-6480The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows...
CVE-2015-5001IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8....
CVE-2015-4998Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27,...
CVE-2015-4993Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27,...
CVE-2015-1836Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3....
CVE-2015-1772The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere Big...
CVE-2015-6934Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCe...
CVE-2015-7756The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before ...
CVE-2015-7755CRITICAL9.8Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r...
CVE-2015-6429The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a d...
CVE-2015-6556EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows ...
CVE-2015-6428Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP reques...
CVE-2015-6427Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggeri...
CVE-2015-6426Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitr...
CVE-2015-6424The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass i...
CVE-2015-8602The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remot...
CVE-2015-8601The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket f...
CVE-2015-8600The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive...
CVE-2015-8369SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execu...
CVE-2015-8368ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u...
CVE-2015-8341The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and i...
CVE-2015-8340The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly release locks, which might ...
CVE-2015-8339The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain...
CVE-2015-8338Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2)...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now