2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6962 | — | — | 2.1% | Sep 17, 2015 | SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2015-6973 | — | — | 64.8% | Sep 16, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to ... |
| CVE-2015-6972 | — | — | 8.0% | Sep 16, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject ... |
| CVE-2015-6929 | — | — | 1.2% | Sep 16, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and Networks and Nokia S... |
| CVE-2015-5465 | — | — | 0.9% | Sep 16, 2015 | Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allow... |
| CVE-2015-3623 | — | — | 15.8% | Sep 16, 2015 | XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server... |
| CVE-2015-1173 | — | — | 2.2% | Sep 16, 2015 | Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (... |
| CVE-2015-6969 | — | — | 1.9% | Sep 16, 2015 | Cross-site scripting (XSS) vulnerability in js/2k11.min.js in the 2k11 theme in Serendipity before 2.0.2 allows remote a... |
| CVE-2015-6968 | — | — | 2.1% | Sep 16, 2015 | Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.p... |
| CVE-2015-6967 | — | — | 49.3% | Sep 16, 2015 | Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to... |
| CVE-2015-6966 | — | — | 0.7% | Sep 16, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack t... |
| CVE-2015-6965 | — | — | 3.0% | Sep 16, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for Wo... |
| CVE-2015-6829 | — | — | 2.4% | Sep 16, 2015 | Multiple SQL injection vulnerabilities in the getip function in wp-limit-login-attempts.php in the WP Limit Login Attemp... |
| CVE-2015-6828 | — | — | 1.9% | Sep 16, 2015 | The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and earlier for WordPress ... |
| CVE-2015-5956 | — | — | 2.0% | Sep 16, 2015 | The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authentica... |
| CVE-2015-5440 | — | — | 0.6% | Sep 16, 2015 | HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users ... |
| CVE-2015-2136 | — | — | 1.8% | Sep 16, 2015 | HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspe... |
| CVE-2015-5426 | — | — | 0.8% | Sep 16, 2015 | Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vec... |
| CVE-2015-5197 | — | — | — | Sep 15, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-6949 | — | — | 7.0% | Sep 15, 2015 | Stack-based buffer overflow in the ASUS TM-AC1900 router allows remote attackers to execute arbitrary code via crafted H... |
| CVE-2015-6948 | — | — | 4.1% | Sep 15, 2015 | Heap-based buffer overflow in the Microsoft Word document conversion feature in Corel WordPerfect allows remote attacker... |
| CVE-2015-6947 | — | — | — | Sep 15, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-6946. Reason: This issue was MERGED into CVE-201... |
| CVE-2015-6946 | — | — | 20.0% | Sep 15, 2015 | Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers t... |
| CVE-2015-6945 | — | — | 3.5% | Sep 15, 2015 | Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary we... |
| CVE-2015-6944 | — | — | 2.4% | Sep 15, 2015 | Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the a... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now