2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-3117 | — | — | 5.3% | Jul 9, 2015 | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481... |
| CVE-2015-3116 | — | — | 3.6% | Jul 9, 2015 | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481... |
| CVE-2015-3115 | — | — | 4.4% | Jul 9, 2015 | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481... |
| CVE-2015-3114 | — | — | 4.1% | Jul 9, 2015 | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481... |
| CVE-2015-5380 | — | — | 3.0% | Jul 9, 2015 | The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js... |
| CVE-2015-5461 | — | — | 6.3% | Jul 8, 2015 | Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for ... |
| CVE-2015-5460 | — | — | 2.5% | Jul 8, 2015 | Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to i... |
| CVE-2015-4616 | — | — | 10.5% | Jul 8, 2015 | Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allo... |
| CVE-2015-4614 | — | — | 5.2% | Jul 8, 2015 | Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow ... |
| CVE-2015-5459 | — | — | 3.5% | Jul 8, 2015 | SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PM... |
| CVE-2015-5458 | — | — | 2.5% | Jul 8, 2015 | Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions ... |
| CVE-2015-5457 | — | — | 4.7% | Jul 8, 2015 | PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allow... |
| CVE-2015-5456 | — | — | 2.1% | Jul 8, 2015 | Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remo... |
| CVE-2015-5455 | — | — | 1.5% | Jul 8, 2015 | Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web scr... |
| CVE-2015-5454 | — | — | 1.6% | Jul 8, 2015 | Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML v... |
| CVE-2015-5453 | — | — | 57.3% | Jul 8, 2015 | Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell... |
| CVE-2015-5452 | — | — | 3.4% | Jul 8, 2015 | SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitr... |
| CVE-2015-1796 | — | — | 1.3% | Jul 8, 2015 | The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust ca... |
| CVE-2015-5119 | CRITICAL | 9.8 | 99.3% | Jul 8, 2015 | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.... |
| CVE-2015-4620 | — | — | 37.9% | Jul 8, 2015 | name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recurs... |
| CVE-2015-4243 | — | — | 0.8% | Jul 8, 2015 | The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a den... |
| CVE-2015-4242 | — | — | 1.0% | Jul 8, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 5.4.1.2 and 6.0.0 in FireSIGHT Manage... |
| CVE-2015-4241 | — | — | 0.7% | Jul 8, 2015 | Cisco Adaptive Security Appliance (ASA) Software 9.3(2) allows remote attackers to cause a denial of service (system rel... |
| CVE-2015-4240 | — | — | 2.4% | Jul 8, 2015 | Cisco IP Communicator 8.6(4) allows remote attackers to cause a denial of service (service outage) via an unspecified UR... |
| CVE-2015-2866 | — | — | 1.6% | Jul 8, 2015 | SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attacke... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now