2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8001 | — | — | 1.6% | Nov 9, 2015 | The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not ... |
| CVE-2015-8096 | — | — | 4.0% | Nov 9, 2015 | Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via ... |
| CVE-2015-8095 | — | — | 1.2% | Nov 9, 2015 | The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes f... |
| CVE-2015-8041 | — | — | 3.4% | Nov 9, 2015 | Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote at... |
| CVE-2015-7940 | — | — | 4.8% | Nov 9, 2015 | The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easie... |
| CVE-2015-7295 | — | — | 4.9% | Nov 9, 2015 | hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are... |
| CVE-2015-5218 | — | — | 0.6% | Nov 9, 2015 | Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of servi... |
| CVE-2015-3240 | — | — | 2.8% | Nov 9, 2015 | The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers t... |
| CVE-2015-5734 | — | — | 7.4% | Nov 9, 2015 | Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPres... |
| CVE-2015-5733 | — | — | 5.6% | Nov 9, 2015 | Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js i... |
| CVE-2015-5732 | — | — | 8.0% | Nov 9, 2015 | Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-wid... |
| CVE-2015-5731 | — | — | 3.9% | Nov 9, 2015 | Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers t... |
| CVE-2015-5730 | — | — | 8.4% | Nov 9, 2015 | The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not u... |
| CVE-2015-2213 | — | — | 11.0% | Nov 9, 2015 | SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 a... |
| CVE-2015-2697 | — | — | 4.1% | Nov 9, 2015 | The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authe... |
| CVE-2015-2696 | — | — | 4.5% | Nov 9, 2015 | lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allow... |
| CVE-2015-2695 | — | — | 6.2% | Nov 9, 2015 | lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, whic... |
| CVE-2015-7412 | — | — | 1.0% | Nov 8, 2015 | The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decrypt... |
| CVE-2015-5044 | — | — | 0.5% | Nov 8, 2015 | The Flow Collector in IBM Security QRadar QFLOW 7.1.x before 7.1 MR2 Patch 11 IF3 and 7.2.x before 7.2.5 Patch 4 IF3 all... |
| CVE-2015-5043 | — | — | 0.3% | Nov 8, 2015 | diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to ... |
| CVE-2015-5019 | — | — | 0.9% | Nov 8, 2015 | IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated... |
| CVE-2015-5015 | — | — | 2.1% | Nov 8, 2015 | IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive info... |
| CVE-2015-5005 | — | — | 1.7% | Nov 8, 2015 | CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by... |
| CVE-2015-4966 | — | — | 1.5% | Nov 8, 2015 | IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo A... |
| CVE-2015-4963 | — | — | 3.3% | Nov 8, 2015 | IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation req... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now