2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2320 | — | — | 3.5% | Jan 8, 2018 | The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-sid... |
| CVE-2015-2319 | — | — | 3.2% | Jan 8, 2018 | The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_R... |
| CVE-2015-2318 | — | — | 2.0% | Jan 8, 2018 | The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequen... |
| CVE-2015-8008 | — | — | 2.8% | Dec 29, 2017 | The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allow... |
| CVE-2015-3302 | — | — | 21.7% | Dec 29, 2017 | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1... |
| CVE-2015-7889 | — | — | 2.2% | Dec 28, 2017 | The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f... |
| CVE-2015-3637 | — | — | 1.4% | Dec 28, 2017 | SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute ... |
| CVE-2015-7669 | — | — | 7.1% | Dec 27, 2017 | Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the ... |
| CVE-2015-7668 | — | — | 2.1% | Dec 27, 2017 | Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPre... |
| CVE-2015-7667 | — | — | 1.5% | Dec 27, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/ads... |
| CVE-2015-7666 | — | — | 1.8% | Dec 27, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functio... |
| CVE-2015-7324 | — | — | 1.8% | Dec 27, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) compo... |
| CVE-2015-6237 | — | — | 1.7% | Dec 27, 2017 | The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass au... |
| CVE-2015-7224 | — | — | 1.7% | Dec 21, 2017 | puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a databas... |
| CVE-2015-4100 | — | — | 0.7% | Dec 21, 2017 | Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by l... |
| CVE-2015-8470 | — | — | 1.6% | Dec 11, 2017 | The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an... |
| CVE-2015-6502 | — | — | 1.1% | Dec 11, 2017 | Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to ... |
| CVE-2015-7269 | — | — | 0.3% | Nov 27, 2017 | Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow... |
| CVE-2015-7268 | — | — | 0.3% | Nov 27, 2017 | Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Window... |
| CVE-2015-7267 | — | — | 0.3% | Nov 27, 2017 | Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode ... |
| CVE-2015-3934 | — | — | 3.1% | Nov 21, 2017 | Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands vi... |
| CVE-2015-7501 | — | — | 83.3% | Nov 9, 2017 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5... |
| CVE-2015-3933 | — | — | 3.8% | Nov 8, 2017 | Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote ... |
| CVE-2015-7878 | — | — | 0.6% | Nov 6, 2017 | Cross-site scripting (XSS) vulnerability in the Taxonomy Find module 6.x-2.x through 6.x-1.2 and 7.x-2.x through 7.x-1.0... |
| CVE-2015-9245 | — | — | 1.9% | Oct 31, 2017 | Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to s... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now