2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4225 | — | — | 1.4% | Jun 27, 2015 | Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properl... |
| CVE-2015-4199 | — | — | 2.1% | Jun 27, 2015 | Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UB... |
| CVE-2015-1269 | — | — | 1.8% | Jun 26, 2015 | The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not... |
| CVE-2015-1268 | — | — | 2.3% | Jun 26, 2015 | bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creatio... |
| CVE-2015-1267 | — | — | 1.5% | Jun 26, 2015 | Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of... |
| CVE-2015-1266 | — | — | 1.5% | Jun 26, 2015 | content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consi... |
| CVE-2015-4224 | — | — | 0.5% | Jun 26, 2015 | Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands ... |
| CVE-2015-4222 | — | — | 2.0% | Jun 26, 2015 | SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authent... |
| CVE-2015-4221 | — | — | 2.3% | Jun 26, 2015 | Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passw... |
| CVE-2015-4217 | — | — | 2.2% | Jun 26, 2015 | The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and ... |
| CVE-2015-4216 | — | — | 3.3% | Jun 26, 2015 | The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and ... |
| CVE-2015-3242 | — | — | — | Jun 26, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-1159 | — | — | 7.3% | Jun 26, 2015 | Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS b... |
| CVE-2015-1158 | — | — | 29.9% | Jun 26, 2015 | The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va... |
| CVE-2015-4223 | — | — | 2.5% | Jun 25, 2015 | Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribu... |
| CVE-2015-4220 | — | — | 2.2% | Jun 25, 2015 | Cross-site scripting (XSS) vulnerability in Cisco Unified Presence Server 9.1(1) allows remote attackers to inject arbit... |
| CVE-2015-1851 | — | — | 2.6% | Jun 25, 2015 | OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows... |
| CVE-2015-5068 | — | — | 2.9% | Jun 24, 2015 | XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to read arbitrary files or poss... |
| CVE-2015-5067 | — | — | 2.6% | Jun 24, 2015 | The (1) Cross-System Tools and (2) Data Transfer Workbench in SAP NetWeaver have hardcoded credentials, which allows rem... |
| CVE-2015-5066 | — | — | 3.8% | Jun 24, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar... |
| CVE-2015-5065 | — | — | 16.3% | Jun 24, 2015 | Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic ... |
| CVE-2015-5064 | — | — | 1.9% | Jun 24, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow ... |
| CVE-2015-5063 | — | — | 1.9% | Jun 24, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework 3.1.13 allow remote attackers to inj... |
| CVE-2015-5062 | — | — | 2.0% | Jun 24, 2015 | Open redirect vulnerability in SilverStripe CMS & Framework 3.1.13 allows remote attackers to redirect users to arbitrar... |
| CVE-2015-5061 | — | — | 2.4% | Jun 24, 2015 | Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows rem... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now