2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6348 | — | — | 1.4% | Oct 30, 2015 | The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows ... |
| CVE-2015-6347 | — | — | 1.4% | Oct 30, 2015 | The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass in... |
| CVE-2015-6346 | — | — | 1.4% | Oct 30, 2015 | Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers t... |
| CVE-2015-6345 | — | — | 1.4% | Oct 30, 2015 | SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote a... |
| CVE-2015-6344 | — | — | 1.4% | Oct 30, 2015 | The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9.3(4.1.11) allows remote authent... |
| CVE-2015-7899 | — | — | 2.0% | Oct 29, 2015 | The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obt... |
| CVE-2015-7859 | — | — | 2.1% | Oct 29, 2015 | The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers... |
| CVE-2015-7858 | — | — | 84.8% | Oct 29, 2015 | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un... |
| CVE-2015-7857 | — | — | 93.9% | Oct 29, 2015 | SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p... |
| CVE-2015-7713 | — | — | 3.7% | Oct 29, 2015 | OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group... |
| CVE-2015-7297 | — | — | 100.0% | Oct 29, 2015 | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un... |
| CVE-2015-5955 | — | — | 1.1% | Oct 29, 2015 | ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instan... |
| CVE-2015-5285 | — | — | 6.0% | Oct 29, 2015 | CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduc... |
| CVE-2015-3230 | — | — | 2.6% | Oct 29, 2015 | 389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference wh... |
| CVE-2015-5292 | — | — | 3.7% | Oct 29, 2015 | Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Servic... |
| CVE-2015-6006 | — | — | 3.7% | Oct 29, 2015 | The AddUserFinding implementation in Medicomp MEDCIN Engine 2.22.20153.x before 2.22.20153.226 might allow remote attack... |
| CVE-2015-5671 | — | — | 1.4% | Oct 29, 2015 | Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to bypass intended access restrictions and read arbi... |
| CVE-2015-5670 | — | — | 1.2% | Oct 29, 2015 | Cross-site scripting (XSS) vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to injec... |
| CVE-2015-5669 | — | — | 2.0% | Oct 29, 2015 | Techno Project Japan Enisys Gw before 1.4.1 allows remote authenticated users to write to arbitrary files and consequent... |
| CVE-2015-5668 | — | — | 1.3% | Oct 29, 2015 | SQL injection vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to execute arbitrary ... |
| CVE-2015-5040 | — | — | 3.3% | Oct 29, 2015 | Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attac... |
| CVE-2015-4997 | — | — | 2.0% | Oct 29, 2015 | IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted requ... |
| CVE-2015-4994 | — | — | 3.3% | Oct 29, 2015 | Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attac... |
| CVE-2015-2901 | — | — | 3.2% | Oct 29, 2015 | Multiple stack-based buffer overflows in Medicomp MEDCIN Engine 2.22.20142.166 might allow remote attackers to execute a... |
| CVE-2015-2900 | — | — | 3.1% | Oct 29, 2015 | The AddUserFinding add_userfinding2 function in Medicomp MEDCIN Engine before 2.22.20153.226 allows remote attackers to ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now