2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7808 | — | — | 80.6% | Nov 24, 2015 | The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH... |
| CVE-2015-7496 | — | — | 0.4% | Nov 24, 2015 | GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the... |
| CVE-2015-5281 | — | — | 0.3% | Nov 24, 2015 | The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users t... |
| CVE-2015-5053 | — | — | 1.7% | Nov 24, 2015 | The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Lin... |
| CVE-2015-0856 | — | — | 0.4% | Nov 24, 2015 | daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to ga... |
| CVE-2015-6380 | — | — | 1.1% | Nov 24, 2015 | An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 d... |
| CVE-2015-6377 | — | — | 1.9% | Nov 24, 2015 | Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memo... |
| CVE-2015-8320 | — | — | 4.4% | Nov 23, 2015 | Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for ... |
| CVE-2015-5275 | — | — | — | Nov 23, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-5257. Reason: This candidate is a reservation du... |
| CVE-2015-5256 | — | — | 4.2% | Nov 23, 2015 | Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript w... |
| CVE-2015-5451 | — | — | 1.5% | Nov 23, 2015 | Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remo... |
| CVE-2015-7036 | — | — | 39.3% | Nov 22, 2015 | The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers ... |
| CVE-2015-5859 | — | — | 1.5% | Nov 22, 2015 | The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly recognize the HSTS pr... |
| CVE-2015-5787 | — | — | 1.4% | Nov 22, 2015 | The kernel in Apple iOS before 8.4.1 does not properly restrict debugging features, which allows attackers to bypass bac... |
| CVE-2015-7913 | — | — | 0.4% | Nov 21, 2015 | ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute ar... |
| CVE-2015-7912 | — | — | 3.2% | Nov 21, 2015 | The Ice Faces servlet in ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows ... |
| CVE-2015-7777 | — | — | 1.8% | Nov 21, 2015 | Cross-site scripting (XSS) vulnerability in index.php in JosephErnest Void before 2015-10-02 allows remote attackers to ... |
| CVE-2015-7291 | — | — | 1.0% | Nov 21, 2015 | Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, ... |
| CVE-2015-7290 | — | — | 1.2% | Nov 21, 2015 | Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG8... |
| CVE-2015-7289 | — | — | 2.1% | Nov 21, 2015 | Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded admin... |
| CVE-2015-6376 | — | — | 0.6% | Nov 21, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows rem... |
| CVE-2015-6375 | — | — | 0.3% | Nov 21, 2015 | The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obt... |
| CVE-2015-7773 | — | — | 1.3% | Nov 20, 2015 | Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authe... |
| CVE-2015-7772 | — | — | 1.2% | Nov 20, 2015 | Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for And... |
| CVE-2015-7771 | — | — | 1.2% | Nov 20, 2015 | Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for And... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now