2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-5282Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
CVE-2015-4669The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the sy...
CVE-2015-4668Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit...
CVE-2015-4667Multiple hardcoded credentials in Xsuite 2.x.
CVE-2015-3887Untrusted search path vulnerability in ProxyChains-NG before 4.9 allows local users to gain privileges via a Trojan hors...
CVE-2015-5284ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem,...
CVE-2015-4706Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web scrip...
CVE-2015-3296Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web ...
CVE-2015-0276Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2.
CVE-2015-9232The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Deleg...
CVE-2015-9231iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature wa...
CVE-2015-7347Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
CVE-2015-6673Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32.
CVE-2015-5608Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
CVE-2015-2927node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
CVE-2015-2826WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
CVE-2015-1866Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.
CVE-2015-0162IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges.
CVE-2015-8224Huawei P8 before GRA-CL00C92B210, before GRA-L09C432B200, before GRA-TL00C01B210, and before GRA-UL00C00B210 allows remo...
CVE-2015-5607Cross-site request forgery in the REST API in IPython 2 and 3.
CVE-2015-5248Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
CVE-2015-5179FreeIPA might display user data improperly via vectors involving non-printable characters.
CVE-2015-4074Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read ar...
CVE-2015-4073Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to exe...
CVE-2015-4072Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote att...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now