2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5143 | — | — | 7.3% | Jul 14, 2015 | The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows rem... |
| CVE-2015-4270 | — | — | 1.5% | Jul 14, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.5 and 6.0.0 allow remote at... |
| CVE-2015-4268 | — | — | 1.5% | Jul 14, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.... |
| CVE-2015-3007 | — | — | 0.4% | Jul 14, 2015 | The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X... |
| CVE-2015-1946 | — | — | 0.4% | Jul 14, 2015 | IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSp... |
| CVE-2015-1936 | — | — | 1.7% | Jul 14, 2015 | The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when ... |
| CVE-2015-1927 | — | — | 2.1% | Jul 14, 2015 | The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.... |
| CVE-2015-5521 | MEDIUM | 4.8 | 0.7% | Jul 14, 2015 | Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or... |
| CVE-2015-5520 | — | — | 3.6% | Jul 14, 2015 | Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allow... |
| CVE-2015-5519 | — | — | 2.2% | Jul 14, 2015 | Cross-site scripting (XSS) vulnerability in the applyConvolution demo in WideImage 11.02.19 allows remote attackers to i... |
| CVE-2015-5397 | — | — | 1.4% | Jul 14, 2015 | Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote atta... |
| CVE-2015-5147 | — | — | 2.5% | Jul 14, 2015 | Stack-based buffer overflow in the header_anchor function in the HTML renderer in Redcarpet before 3.3.2 allows attacker... |
| CVE-2015-3279 | — | — | 6.9% | Jul 14, 2015 | Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a den... |
| CVE-2015-3258 | — | — | 8.3% | Jul 14, 2015 | Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 ... |
| CVE-2015-1561 | — | — | 9.1% | Jul 14, 2015 | The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centre... |
| CVE-2015-1560 | — | — | 6.7% | Jul 14, 2015 | SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis... |
| CVE-2015-4272 | — | — | 1.5% | Jul 14, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communications Manager (formerly... |
| CVE-2015-4269 | — | — | 1.6% | Jul 14, 2015 | The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users ... |
| CVE-2015-1944 | — | — | 1.4% | Jul 14, 2015 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows ... |
| CVE-2015-1917 | — | — | 1.8% | Jul 14, 2015 | Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through... |
| CVE-2015-1887 | — | — | 2.5% | Jul 14, 2015 | IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attacker... |
| CVE-2015-5123 | CRITICAL | 9.8 | 18.5% | Jul 14, 2015 | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13... |
| CVE-2015-5122 | CRITICAL | 9.8 | 93.7% | Jul 14, 2015 | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player... |
| CVE-2015-8176 | — | — | — | Jul 13, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8176. Reason: This candidate is a duplicate of... |
| CVE-2015-1961 | — | — | 2.4% | Jul 13, 2015 | The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now