2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4414 | — | — | 19.0% | Jun 17, 2015 | Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)... |
| CVE-2015-4342 | — | — | 3.2% | Jun 17, 2015 | SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspeci... |
| CVE-2015-4338 | — | — | 2.3% | Jun 17, 2015 | Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to injec... |
| CVE-2015-4337 | — | — | 1.6% | Jun 17, 2015 | Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to ... |
| CVE-2015-4336 | — | — | 2.7% | Jun 17, 2015 | cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary co... |
| CVE-2015-3429 | — | — | 3.8% | Jun 17, 2015 | Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, ... |
| CVE-2015-2803 | — | — | 2.5% | Jun 17, 2015 | SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3... |
| CVE-2015-2665 | — | — | 2.2% | Jun 17, 2015 | Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script o... |
| CVE-2015-4550 | — | — | 1.3% | Jun 17, 2015 | The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4... |
| CVE-2015-4190 | — | — | 1.3% | Jun 17, 2015 | Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vortex on Cloud Portal appliances allows man-in-the-middle attac... |
| CVE-2015-4188 | — | — | 1.9% | Jun 17, 2015 | SQL injection vulnerability in the Manager interface in Cisco Prime Collaboration 10.5(1) allows remote attackers to exe... |
| CVE-2015-4186 | — | — | 0.6% | Jun 17, 2015 | The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 d... |
| CVE-2015-4183 | — | — | 0.6% | Jun 17, 2015 | Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI para... |
| CVE-2015-3318 | — | — | 0.4% | Jun 17, 2015 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.... |
| CVE-2015-3317 | — | — | 0.4% | Jun 17, 2015 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.... |
| CVE-2015-3316 | — | — | 0.5% | Jun 17, 2015 | CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.... |
| CVE-2015-0546 | — | — | 3.4% | Jun 17, 2015 | EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by pro... |
| CVE-2015-4398 | — | — | 1.3% | Jun 16, 2015 | Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupa... |
| CVE-2015-4374 | — | — | 1.1% | Jun 16, 2015 | Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x bef... |
| CVE-2015-4613 | — | — | 0.9% | Jun 16, 2015 | SQL injection vulnerability in the backend module in the Developer Log (devlog) extension before 2.11.4 for TYPO3 allows... |
| CVE-2015-4612 | — | — | 1.0% | Jun 16, 2015 | SQL injection vulnerability in the "FAQ - Frequently Asked Questions" (js_faq) extension before 1.2.1 for TYPO3 allows r... |
| CVE-2015-4611 | — | — | 1.0% | Jun 16, 2015 | SQL injection vulnerability in the Smoelenboek (ncgov_smoelenboek) extension before 1.0.9 for TYPO3 allows remote authen... |
| CVE-2015-4610 | — | — | 1.0% | Jun 16, 2015 | SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated ... |
| CVE-2015-4609 | — | — | 1.0% | Jun 16, 2015 | SQL injection vulnerability in the wt_directory extension before 1.4.2 for TYPO3 allows remote authenticated users to ex... |
| CVE-2015-4608 | — | — | 0.8% | Jun 16, 2015 | Cross-site scripting (XSS) vulnerability in the BE User Log (beko_beuserlog) extension 1.1.1 and earlier for TYPO3 allow... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now