2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4675 | — | — | 4.7% | Jun 19, 2015 | Buffer overflow in the Tiny SRP library (aka TinySRP) allows remote attackers to cause a denial of service (crash) or po... |
| CVE-2015-4641 | — | — | 3.7% | Jun 19, 2015 | Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5,... |
| CVE-2015-4640 | — | — | 0.9% | Jun 19, 2015 | The SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices relies on an HTTP con... |
| CVE-2015-2865 | — | — | — | Jun 19, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-4640, CVE-2015-4641. Reason: this ID was inten... |
| CVE-2015-2797 | — | — | 77.6% | Jun 19, 2015 | Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502... |
| CVE-2015-4195 | — | — | 1.6% | Jun 19, 2015 | Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET o... |
| CVE-2015-4194 | — | — | 2.6% | Jun 19, 2015 | The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login ... |
| CVE-2015-4191 | — | — | 3.0% | Jun 19, 2015 | Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via a malformed IPv6 pa... |
| CVE-2015-4661 | — | — | 2.4% | Jun 18, 2015 | Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or... |
| CVE-2015-4660 | — | — | 2.4% | Jun 18, 2015 | Cross-site scripting (XSS) vulnerability in Enhanced SQL Portal 5.0.7961 allows remote attackers to inject arbitrary web... |
| CVE-2015-4659 | — | — | 1.1% | Jun 18, 2015 | Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the auth... |
| CVE-2015-4658 | — | — | 1.3% | Jun 18, 2015 | Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute ... |
| CVE-2015-4657 | — | — | 1.2% | Jun 18, 2015 | Cross-site scripting (XSS) vulnerability in Mailbird 2.0.16.0 and earlier allows remote attackers to inject arbitrary we... |
| CVE-2015-4656 | — | — | 1.3% | Jun 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station before 6.3-2945 allow remote attackers to ... |
| CVE-2015-4655 | — | — | 1.5% | Jun 18, 2015 | Cross-site scripting (XSS) vulnerability in Synology DiskStation Manager (DSM) before 5.2-5565 Update 1 allows remote at... |
| CVE-2015-4654 | — | — | 1.3% | Jun 18, 2015 | SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary ... |
| CVE-2015-4587 | — | — | 1.0% | Jun 18, 2015 | Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows r... |
| CVE-2015-4420 | — | — | 1.6% | Jun 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitr... |
| CVE-2015-4140 | — | — | 1.1% | Jun 18, 2015 | Cross-site request forgery (CSRF) vulnerability in the WP Smiley plugin 1.4.1 for WordPress allows remote attackers to h... |
| CVE-2015-4139 | — | — | 1.6% | Jun 18, 2015 | Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote aut... |
| CVE-2015-3897 | — | — | 17.7% | Jun 18, 2015 | Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via ... |
| CVE-2015-3422 | — | — | 1.9% | Jun 18, 2015 | Cross-site scripting (XSS) vulnerability in SearchBlox before 8.2.1 allows remote attackers to inject arbitrary web scri... |
| CVE-2015-4628 | — | — | 1.6% | Jun 18, 2015 | SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 ... |
| CVE-2015-2861 | — | — | 1.2% | Jun 18, 2015 | Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack... |
| CVE-2015-4454 | — | — | 2.3% | Jun 17, 2015 | SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows r... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now