2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4207 | — | — | 2.7% | Jun 23, 2015 | Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive ... |
| CVE-2015-4205 | — | — | 0.9% | Jun 23, 2015 | Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card... |
| CVE-2015-4203 | — | — | 2.2% | Jun 23, 2015 | Race condition in Cisco IOS 12.2SCH in the Performance Routing Engine (PRE) module on uBR10000 devices, when NetFlow and... |
| CVE-2015-4189 | — | — | 0.6% | Jun 23, 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Data Center Analytics Framework (DCAF) 1.4 allows remote attack... |
| CVE-2015-4204 | — | — | 2.7% | Jun 23, 2015 | Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authentic... |
| CVE-2015-4200 | — | — | 3.5% | Jun 23, 2015 | Memory leak in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR d... |
| CVE-2015-3237 | — | — | 9.3% | Jun 22, 2015 | The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive i... |
| CVE-2015-3236 | — | — | 8.2% | Jun 22, 2015 | cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reu... |
| CVE-2015-3234 | — | — | 1.9% | Jun 22, 2015 | The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' account... |
| CVE-2015-3233 | — | — | 2.8% | Jun 22, 2015 | Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to... |
| CVE-2015-3232 | — | — | 1.9% | Jun 22, 2015 | Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users t... |
| CVE-2015-3231 | — | — | 1.7% | Jun 22, 2015 | The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated ... |
| CVE-2015-4714 | — | — | 1.0% | Jun 22, 2015 | Cross-site scripting (XSS) vulnerability in the DreamBox DM500-S allows remote attackers to inject arbitrary web script ... |
| CVE-2015-4713 | — | — | 1.1% | Jun 22, 2015 | SQL injection vulnerability in ApPHP Hotel Site 3.x.x allows remote editors to execute arbitrary SQL commands via the pi... |
| CVE-2015-4590 | — | — | 2.6% | Jun 22, 2015 | The extractFrom function in Internals/QuotedString.cpp in Arduino JSON before 4.5 allows remote attackers to cause a den... |
| CVE-2015-0526 | — | — | 1.4% | Jun 22, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Validation Manager (RVM) 3.2 before build 201 allow remot... |
| CVE-2015-4202 | — | — | 1.8% | Jun 20, 2015 | Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP ... |
| CVE-2015-4198 | — | — | 2.2% | Jun 20, 2015 | Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with softwar... |
| CVE-2015-4197 | — | — | 0.8% | Jun 20, 2015 | Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (device crash) by sending ... |
| CVE-2015-2723 | — | — | — | Jun 20, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-4000. Reason: This candidate is a duplicate of... |
| CVE-2015-4201 | — | — | 3.0% | Jun 20, 2015 | The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59... |
| CVE-2015-4679 | — | — | 1.5% | Jun 19, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Airties RT-210 allow remote attackers to inj... |
| CVE-2015-4678 | — | — | 1.9% | Jun 19, 2015 | SQL injection vulnerability in Persian Car CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cat... |
| CVE-2015-4677 | — | — | 1.1% | Jun 19, 2015 | Cross-site request forgery (CSRF) vulnerability in FiverrScript (aka Fiverr Script) 7.2 allows remote attackers to hijac... |
| CVE-2015-4676 | — | — | 1.5% | Jun 19, 2015 | SQL injection vulnerability in ticket.php in TickFa 1.x allows remote authenticated users to execute arbitrary SQL comma... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now