2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6922 | CRITICAL | 9.8 | 82.1% | Feb 17, 2020 | Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before ... |
| CVE-2015-0258 | HIGH | 8.8 | 3.8% | Feb 17, 2020 | Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before ... |
| CVE-2015-1387 | — | — | — | Feb 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1454. Reason: This candidate is a reservation du... |
| CVE-2015-6589 | HIGH | 8.8 | 13.6% | Feb 13, 2020 | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before ... |
| CVE-2015-3309 | HIGH | 7.5 | 2.3% | Feb 13, 2020 | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to rea... |
| CVE-2015-7890 | MEDIUM | 5.5 | 1.3% | Feb 12, 2020 | Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung ... |
| CVE-2015-5617 | CRITICAL | 9.8 | 2.0% | Feb 12, 2020 | SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attac... |
| CVE-2015-7508 | HIGH | 8.8 | 2.8% | Feb 12, 2020 | Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attac... |
| CVE-2015-2287 | — | — | — | Feb 11, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A typo caused the wrong ID to be used. Note... |
| CVE-2015-5741 | CRITICAL | 9.8 | 2.7% | Feb 8, 2020 | The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remot... |
| CVE-2015-3423 | HIGH | 8.8 | 2.4% | Feb 8, 2020 | Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated us... |
| CVE-2015-2207 | MEDIUM | 5.4 | 0.9% | Feb 8, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote aut... |
| CVE-2015-2062 | HIGH | 7.2 | 2.4% | Feb 8, 2020 | Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remo... |
| CVE-2015-1394 | MEDIUM | 5.4 | 2.3% | Feb 8, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote... |
| CVE-2015-2909 | CRITICAL | 9.8 | 2.9% | Feb 6, 2020 | Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the... |
| CVE-2015-6000 | HIGH | 8.8 | 40.2% | Feb 6, 2020 | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger... |
| CVE-2015-5628 | CRITICAL | 9.8 | 6.7% | Feb 5, 2020 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM... |
| CVE-2015-5627 | CRITICAL | 9.8 | 4.2% | Feb 5, 2020 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM... |
| CVE-2015-5626 | CRITICAL | 9.8 | 4.2% | Feb 5, 2020 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM... |
| CVE-2015-0102 | HIGH | 8.1 | 1.7% | Feb 5, 2020 | IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier ... |
| CVE-2015-2802 | HIGH | 7.5 | 6.4% | Feb 4, 2020 | An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Man... |
| CVE-2015-3613 | CRITICAL | 9.8 | 2.2% | Feb 4, 2020 | A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page |
| CVE-2015-3612 | MEDIUM | 5.4 | 0.8% | Feb 4, 2020 | A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspec... |
| CVE-2015-3611 | HIGH | 8.8 | 5.6% | Feb 4, 2020 | A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspe... |
| CVE-2015-6815 | LOW | 3.5 | 1.0% | Jan 31, 2020 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now