2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7596 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation director... |
| CVE-2015-5079 | — | — | 17.6% | Feb 28, 2018 | Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit... |
| CVE-2015-4117 | — | — | 11.2% | Feb 28, 2018 | Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac... |
| CVE-2015-3898 | — | — | 6.1% | Feb 28, 2018 | Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arb... |
| CVE-2015-5725 | — | — | 2.4% | Feb 21, 2018 | SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote at... |
| CVE-2015-5316 | — | — | 3.4% | Feb 21, 2018 | The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is en... |
| CVE-2015-5315 | — | — | 2.6% | Feb 21, 2018 | The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembl... |
| CVE-2015-5314 | — | — | 2.3% | Feb 21, 2018 | The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassem... |
| CVE-2015-6569 | — | — | 2.0% | Feb 21, 2018 | Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to c... |
| CVE-2015-0203 | — | — | 8.9% | Feb 21, 2018 | The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon ... |
| CVE-2015-0262 | — | — | — | Feb 21, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-6544 | — | — | 5.6% | Feb 20, 2018 | Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows... |
| CVE-2015-9256 | — | — | 1.1% | Feb 20, 2018 | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore moun... |
| CVE-2015-9255 | — | — | 1.1% | Feb 20, 2018 | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, confi... |
| CVE-2015-9254 | — | — | 1.1% | Feb 20, 2018 | Datto ALTO and SIRIS devices have a default VNC password. |
| CVE-2015-2081 | — | — | 2.9% | Feb 20, 2018 | Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts. |
| CVE-2015-9253 | — | — | 4.3% | Feb 19, 2018 | An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master proce... |
| CVE-2015-2324 | — | — | 0.9% | Feb 19, 2018 | Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allo... |
| CVE-2015-9252 | — | — | 1.1% | Feb 13, 2018 | An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral... |
| CVE-2015-1862 | — | — | 3.1% | Feb 9, 2018 | The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot... |
| CVE-2015-2329 | — | — | 1.2% | Feb 8, 2018 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to... |
| CVE-2015-4400 | — | — | 0.7% | Feb 6, 2018 | Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless networ... |
| CVE-2015-3619 | — | — | 0.8% | Feb 6, 2018 | Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! a... |
| CVE-2015-3618 | — | — | 1.4% | Feb 6, 2018 | Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attack... |
| CVE-2015-5674 | — | — | 2.6% | Feb 5, 2018 | The routed daemon in FreeBSD 9.3 before 9.3-RELEASE-p22, 10.2-RC2 before 10.2-RC2-p1, 10.2-RC1 before 10.2-RC1-p2, 10.2 ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now