2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4290 | — | — | 0.3% | Jul 29, 2015 | The kernel extension in Cisco AnyConnect Secure Mobility Client 4.0(2049) on OS X allows local users to cause a denial o... |
| CVE-2015-4286 | — | — | 1.7% | Jul 29, 2015 | The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted ... |
| CVE-2015-2979 | — | — | 1.4% | Jul 29, 2015 | Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
| CVE-2015-2978 | — | — | 1.3% | Jul 29, 2015 | Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation vi... |
| CVE-2015-2977 | — | — | 2.3% | Jul 29, 2015 | Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, vi... |
| CVE-2015-4288 | — | — | 0.5% | Jul 29, 2015 | The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, a... |
| CVE-2015-4287 | — | — | 1.3% | Jul 29, 2015 | Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intend... |
| CVE-2015-2974 | — | — | 1.3% | Jul 29, 2015 | LEMON-S PHP Gazou BBS plus before 2.36 allows remote attackers to upload arbitrary HTML documents via vectors involving ... |
| CVE-2015-0732 | — | — | 1.8% | Jul 29, 2015 | Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0-193; Email Security ... |
| CVE-2015-4692 | — | — | 0.5% | Jul 27, 2015 | The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a... |
| CVE-2015-3227 | — | — | 4.3% | Jul 26, 2015 | The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, whe... |
| CVE-2015-3226 | — | — | 2.8% | Jul 26, 2015 | Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1... |
| CVE-2015-3225 | — | — | 7.8% | Jul 26, 2015 | lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products... |
| CVE-2015-3224 | — | — | 45.5% | Jul 26, 2015 | request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-... |
| CVE-2015-1872 | — | — | 2.1% | Jul 26, 2015 | The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of compone... |
| CVE-2015-1840 | — | — | 4.5% | Jul 26, 2015 | jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ru... |
| CVE-2015-2848 | — | — | 0.7% | Jul 26, 2015 | Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch before 5.2.19.0_VA allows remote attackers to ... |
| CVE-2015-2847 | — | — | 2.4% | Jul 26, 2015 | Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote... |
| CVE-2015-4945 | — | — | 1.0% | Jul 26, 2015 | Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to b... |
| CVE-2015-2975 | — | — | 1.3% | Jul 26, 2015 | Research Artisan Lite before 1.18 does not ensure that a user has authenticated, which allows remote attackers to perfor... |
| CVE-2015-2976 | — | — | 1.2% | Jul 25, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Research Artisan Lite before 1.18 allow remote attackers to injec... |
| CVE-2015-2973 | — | — | 2.0% | Jul 24, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Welcart plugin before 1.4.18 for WordPress allow remote attac... |
| CVE-2015-0681 | — | — | 2.3% | Jul 24, 2015 | The TFTP server in Cisco IOS 12.2(44)SQ1, 12.2(33)XN1, 12.4(25e)JAM1, 12.4(25e)JAO5m, 12.4(23)JY, 15.0(2)ED1, 15.0(2)EY3... |
| CVE-2015-4262 | — | — | 2.8% | Jul 24, 2015 | The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does ... |
| CVE-2015-4235 | — | — | 2.2% | Jul 24, 2015 | Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) an... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now