2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4461 | — | — | 1.2% | Feb 5, 2018 | Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensiti... |
| CVE-2015-4412 | — | — | 4.8% | Feb 5, 2018 | BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attacker... |
| CVE-2015-4179 | — | — | 0.9% | Feb 5, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Codestyling Localization plugin 1.99.30 and earlier fo... |
| CVE-2015-1418 | — | — | 3.8% | Feb 5, 2018 | The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 b... |
| CVE-2015-1416 | — | — | 3.5% | Feb 5, 2018 | Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEAS... |
| CVE-2015-2186 | — | — | 1.1% | Feb 3, 2018 | The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use ... |
| CVE-2015-2796 | — | — | 1.1% | Feb 2, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject ar... |
| CVE-2015-2204 | — | — | 3.2% | Feb 1, 2018 | Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access ... |
| CVE-2015-2203 | — | — | 2.2% | Feb 1, 2018 | Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive sett... |
| CVE-2015-1142857 | — | — | 2.5% | Jan 23, 2018 | On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF... |
| CVE-2015-9251 | — | — | 30.2% | Jan 18, 2018 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi... |
| CVE-2015-7486 | — | — | 0.7% | Jan 16, 2018 | Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim ... |
| CVE-2015-7485 | — | — | 0.7% | Jan 16, 2018 | Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim ... |
| CVE-2015-7484 | — | — | 1.0% | Jan 16, 2018 | IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remo... |
| CVE-2015-7474 | — | — | 0.7% | Jan 16, 2018 | Cross-site scripting (XSS) vulnerability in Jazz Foundation in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0... |
| CVE-2015-9250 | — | — | 1.7% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmen... |
| CVE-2015-9249 | — | — | 1.1% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/Versi... |
| CVE-2015-9248 | — | — | 0.5% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the titl... |
| CVE-2015-9247 | — | — | 0.5% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyb... |
| CVE-2015-9246 | — | — | 2.9% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archiv... |
| CVE-2015-3888 | — | — | 1.1% | Jan 12, 2018 | Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers ... |
| CVE-2015-2981 | — | — | 0.8% | Jan 12, 2018 | The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-... |
| CVE-2015-2298 | — | — | 2.3% | Jan 12, 2018 | node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information... |
| CVE-2015-1290 | — | — | 3.3% | Jan 9, 2018 | The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote... |
| CVE-2015-1208 | — | — | 1.5% | Jan 9, 2018 | Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers t... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now