2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-3229——fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use...
CVE-2015-2780——Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a cra...
CVE-2015-6358——Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allow...
CVE-2015-8239——The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of...
CVE-2015-7778——Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-...
CVE-2015-7503——Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attacker...
CVE-2015-7384——Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
CVE-2015-6918——salt before 2015.5.5 leaks git usernames and passwords to the log.
CVE-2015-6521——Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.
CVE-2015-5675——The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial...
CVE-2015-5639——niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-t...
CVE-2015-2988——Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to exec...
CVE-2015-2856——Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices ...
CVE-2015-7842——Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R...
CVE-2015-2673——The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC...
CVE-2015-2148——Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.2 allow remote attackers to...
CVE-2015-2147——Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbi...
CVE-2015-2146——Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbi...
CVE-2015-2145——Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to...
CVE-2015-2144——Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticate...
CVE-2015-2143——Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attac...
CVE-2015-2142——Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authe...
CVE-2015-0296——The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r324...
CVE-2015-5246——The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain ac...
CVE-2015-2297——nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application cras...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now