2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4413 | — | — | 2.7% | Jun 24, 2015 | Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend F... |
| CVE-2015-3900 | — | — | 8.9% | Jun 24, 2015 | RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching ge... |
| CVE-2015-2169 | — | — | 7.7% | Jun 24, 2015 | Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker... |
| CVE-2015-4219 | — | — | 2.1% | Jun 24, 2015 | Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.... |
| CVE-2015-4218 | — | — | 2.6% | Jun 24, 2015 | The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to... |
| CVE-2015-4215 | — | — | 1.0% | Jun 24, 2015 | Cisco Wireless LAN Controller (WLC) devices with software 7.5(102.0) and 7.6(1.62) allow remote attackers to cause a den... |
| CVE-2015-4214 | — | — | 2.0% | Jun 24, 2015 | Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by re... |
| CVE-2015-4213 | — | — | 2.6% | Jun 24, 2015 | Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveragin... |
| CVE-2015-4212 | — | — | 2.6% | Jun 24, 2015 | Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstra... |
| CVE-2015-4211 | — | — | 0.4% | Jun 24, 2015 | Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local user... |
| CVE-2015-4208 | — | — | 2.6% | Jun 24, 2015 | Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers... |
| CVE-2015-3112 | — | — | 14.3% | Jun 24, 2015 | Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code ... |
| CVE-2015-3111 | — | — | 19.5% | Jun 24, 2015 | Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac... |
| CVE-2015-3110 | — | — | 16.5% | Jun 24, 2015 | Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to ex... |
| CVE-2015-3109 | — | — | 5.1% | Jun 24, 2015 | Adobe Photoshop CC before 16.0 (aka 2015.0.0) allows attackers to execute arbitrary code or cause a denial of service (m... |
| CVE-2015-2308 | — | — | 1.4% | Jun 24, 2015 | Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2... |
| CVE-2015-3113 | CRITICAL | 9.8 | 99.9% | Jun 23, 2015 | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an... |
| CVE-2015-2859 | — | — | 1.0% | Jun 23, 2015 | Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certi... |
| CVE-2015-2860 | — | — | 2.7% | Jun 23, 2015 | Directory traversal vulnerability in Avigilon Control Center (ACC) 4 before 4.12.0.54 and 5 before 5.4.2.22 allows remot... |
| CVE-2015-0972 | — | — | 1.4% | Jun 23, 2015 | Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which ... |
| CVE-2015-4726 | — | — | 1.5% | Jun 23, 2015 | PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arb... |
| CVE-2015-4725 | — | — | 1.0% | Jun 23, 2015 | Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare 2.0.2 allows remote attackers to inject arbitrary w... |
| CVE-2015-4586 | — | — | 0.9% | Jun 23, 2015 | Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h... |
| CVE-2015-4210 | — | — | 2.2% | Jun 23, 2015 | Cross-site scripting (XSS) vulnerability in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web s... |
| CVE-2015-4209 | — | — | 3.1% | Jun 23, 2015 | Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote at... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now