2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6912 | — | — | 11.8% | Sep 11, 2015 | Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharact... |
| CVE-2015-6911 | — | — | 2.4% | Sep 11, 2015 | SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL c... |
| CVE-2015-6910 | — | — | 2.3% | Sep 11, 2015 | SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL c... |
| CVE-2015-6909 | — | — | 2.1% | Sep 11, 2015 | Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Stat... |
| CVE-2015-6908 | — | — | 19.6% | Sep 11, 2015 | The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a de... |
| CVE-2015-6675 | — | — | 0.8% | Sep 11, 2015 | Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers t... |
| CVE-2015-6466 | — | — | 1.3% | Sep 11, 2015 | Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-4... |
| CVE-2015-6465 | — | — | 2.0% | Sep 11, 2015 | The GoAhead web server on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users... |
| CVE-2015-6464 | — | — | 2.0% | Sep 11, 2015 | The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authentic... |
| CVE-2015-5631 | — | — | 0.6% | Sep 11, 2015 | Cross-site request forgery (CSRF) vulnerability in the Remote UI on Canon PIXMA MG7500 printers allows remote attackers ... |
| CVE-2015-3964 | — | — | 3.4% | Sep 11, 2015 | SMA Solar Sunny WebBox has hardcoded passwords, which makes it easier for remote attackers to obtain access via unspecif... |
| CVE-2015-6827 | — | — | 2.0% | Sep 11, 2015 | Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentica... |
| CVE-2015-6584 | — | — | 2.7% | Sep 11, 2015 | Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers ... |
| CVE-2015-5249 | — | — | — | Sep 10, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-6681 | — | — | 5.6% | Sep 9, 2015 | Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory... |
| CVE-2015-6680 | — | — | 5.1% | Sep 9, 2015 | Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory... |
| CVE-2015-2546 | HIGH | 8.2 | 10.9% | Sep 9, 2015 | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win... |
| CVE-2015-2545 | HIGH | 7.8 | 86.1% | Sep 9, 2015 | Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a c... |
| CVE-2015-2544 | — | — | 9.5% | Sep 9, 2015 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update... |
| CVE-2015-2543 | — | — | 9.5% | Sep 9, 2015 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update... |
| CVE-2015-2542 | — | — | 20.2% | Sep 9, 2015 | Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a den... |
| CVE-2015-2541 | — | — | 19.4% | Sep 9, 2015 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service ... |
| CVE-2015-2536 | — | — | 8.9% | Sep 9, 2015 | Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote ... |
| CVE-2015-2535 | — | — | 11.5% | Sep 9, 2015 | Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated... |
| CVE-2015-2534 | — | — | 1.9% | Sep 9, 2015 | Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now