2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-6922CRITICAL9.8Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before ...
CVE-2015-0258HIGH8.8Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before ...
CVE-2015-1387Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1454. Reason: This candidate is a reservation du...
CVE-2015-6589HIGH8.8Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before ...
CVE-2015-3309HIGH7.5Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to rea...
CVE-2015-7890MEDIUM5.5Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung ...
CVE-2015-5617CRITICAL9.8SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attac...
CVE-2015-7508HIGH8.8Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attac...
CVE-2015-2287Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A typo caused the wrong ID to be used. Note...
CVE-2015-5741CRITICAL9.8The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remot...
CVE-2015-3423HIGH8.8Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated us...
CVE-2015-2207MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote aut...
CVE-2015-2062HIGH7.2Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remo...
CVE-2015-1394MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote...
CVE-2015-2909CRITICAL9.8Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the...
CVE-2015-6000HIGH8.8Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger...
CVE-2015-5628CRITICAL9.8Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM...
CVE-2015-5627CRITICAL9.8Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM...
CVE-2015-5626CRITICAL9.8Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM...
CVE-2015-0102HIGH8.1IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier ...
CVE-2015-2802HIGH7.5An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Man...
CVE-2015-3613CRITICAL9.8A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
CVE-2015-3612MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspec...
CVE-2015-3611HIGH8.8A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspe...
CVE-2015-6815LOW3.5The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now