2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6943 | — | — | 1.2% | Sep 15, 2015 | SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Seren... |
| CVE-2015-5472 | — | — | 3.3% | Sep 15, 2015 | Absolute path traversal vulnerability in lib/download.php in the IBS Mappro plugin before 1.0 for WordPress allows remot... |
| CVE-2015-4947 | — | — | 7.9% | Sep 15, 2015 | Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0... |
| CVE-2015-4980 | — | — | 1.6% | Sep 14, 2015 | Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain ... |
| CVE-2015-1943 | — | — | 2.7% | Sep 14, 2015 | IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x befor... |
| CVE-2015-5998 | — | — | 2.6% | Sep 14, 2015 | Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remot... |
| CVE-2015-5997 | — | — | 1.7% | Sep 14, 2015 | Impero Education Pro before 5105 uses a hardcoded CBC key and initialization vector derived from a hash of the Imp3ro st... |
| CVE-2015-6830 | — | — | 9.8% | Sep 14, 2015 | libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allo... |
| CVE-2015-6290 | — | — | 1.4% | Sep 14, 2015 | Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption fro... |
| CVE-2015-6288 | — | — | 2.2% | Sep 14, 2015 | Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote ... |
| CVE-2015-6287 | — | — | 2.0% | Sep 14, 2015 | Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service... |
| CVE-2015-6286 | — | — | 0.5% | Sep 14, 2015 | Cisco Application Visibility and Control (AVC) 15.3(3)JA, when FlexConnect is enabled, allows remote attackers to cause ... |
| CVE-2015-6285 | — | — | 1.4% | Sep 14, 2015 | Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a d... |
| CVE-2015-4499 | — | — | 3.4% | Sep 14, 2015 | Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long... |
| CVE-2015-2013 | — | — | 2.4% | Sep 14, 2015 | IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and pro... |
| CVE-2015-5270 | — | — | — | Sep 12, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-5226 | — | — | — | Sep 12, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-5630 | — | — | 1.2% | Sep 11, 2015 | Cross-site scripting (XSS) vulnerability in the NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and ... |
| CVE-2015-5629 | — | — | 1.1% | Sep 11, 2015 | The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier fo... |
| CVE-2015-6921 | — | — | 0.8% | Sep 11, 2015 | Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows rem... |
| CVE-2015-6920 | — | — | 3.3% | Sep 11, 2015 | Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote a... |
| CVE-2015-6919 | — | — | 1.0% | Sep 11, 2015 | Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! al... |
| CVE-2015-6915 | — | — | 1.8% | Sep 11, 2015 | SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arb... |
| CVE-2015-6914 | — | — | 3.1% | Sep 11, 2015 | Absolute path traversal vulnerability in SiteFactory CMS 5.5.9 allows remote attackers to read arbitrary files via a ful... |
| CVE-2015-6913 | — | — | 1.9% | Sep 11, 2015 | Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station befo... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now