2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5024 | — | — | 1.0% | Oct 6, 2015 | IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iF... |
| CVE-2015-5022 | — | — | 1.1% | Oct 6, 2015 | IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before ... |
| CVE-2015-4992 | — | — | 0.8% | Oct 6, 2015 | IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via u... |
| CVE-2015-4973 | — | — | 0.9% | Oct 6, 2015 | Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advance... |
| CVE-2015-4971 | — | — | 0.8% | Oct 6, 2015 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Strategic Supply Management Platform and Emptoris Program Manag... |
| CVE-2015-4967 | — | — | 1.0% | Oct 6, 2015 | SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0... |
| CVE-2015-4965 | — | — | 1.0% | Oct 6, 2015 | maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5... |
| CVE-2015-4964 | — | — | 1.5% | Oct 6, 2015 | IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values t... |
| CVE-2015-4944 | — | — | 0.8% | Oct 6, 2015 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX0... |
| CVE-2015-4939 | — | — | 1.0% | Oct 6, 2015 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier Lifecycle Management and Emptoris Program Management 1... |
| CVE-2015-3938 | — | — | 2.2% | Oct 6, 2015 | The HTTP application on Mitsubishi Electric MELSEC FX3G PLC devices before April 2015 allows remote attackers to cause a... |
| CVE-2015-1015 | — | — | 0.4% | Oct 6, 2015 | Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible for... |
| CVE-2015-0988 | — | — | 0.3% | Oct 6, 2015 | Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project source-code files, which ... |
| CVE-2015-0987 | CRITICAL | 10 | 1.2% | Oct 6, 2015 | Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext pa... |
| CVE-2015-7709 | — | — | 79.0% | Oct 5, 2015 | The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b... |
| CVE-2015-7708 | — | — | 1.4% | Oct 5, 2015 | Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web s... |
| CVE-2015-7707 | — | — | 6.0% | Oct 5, 2015 | Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter... |
| CVE-2015-7323 | — | — | 1.7% | Oct 5, 2015 | The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.... |
| CVE-2015-7322 | — | — | 2.3% | Oct 5, 2015 | The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.... |
| CVE-2015-7685 | — | — | 1.7% | Oct 5, 2015 | GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create ... |
| CVE-2015-7684 | — | — | 4.1% | Oct 5, 2015 | Unrestricted file upload in GLPI before 0.85.3 allows remote authenticated users to execute arbitrary code by adding a f... |
| CVE-2015-7392 | — | — | 4.7% | Oct 5, 2015 | Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x... |
| CVE-2015-5687 | — | — | 2.5% | Oct 5, 2015 | system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks an... |
| CVE-2015-4930 | — | — | 2.1% | Oct 4, 2015 | IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute... |
| CVE-2015-2031 | — | — | 1.0% | Oct 4, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 al... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now