2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-0767Cisco Edge 300 software 1.0 and 1.1 on Edge 340 devices allows local users to obtain root privileges via unspecified com...
CVE-2015-0112Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5...
CVE-2015-3950Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hij...
CVE-2015-2951JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.
CVE-2015-2950Directory traversal vulnerability in the Brandon Bowles Open Explorer application before 0.254 Beta for Android allows r...
CVE-2015-2124Unspecified vulnerability in Easy Setup Wizard in HP ThinPro Linux 4.1 through 5.1 and Smart Zero Core 4.3 and 4.4 allow...
CVE-2015-1000Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX c...
CVE-2015-0541Cross-site request forgery (CSRF) vulnerability in EMC RSA Web Threat Detection before 5.1 allows remote attackers to hi...
CVE-2015-0766Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in the Management Center compone...
CVE-2015-0765Cisco ONS 15454 System Software 10.30 and 10.301 allows remote attackers to cause a denial of service (tNetTask CPU cons...
CVE-2015-0764Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka ...
CVE-2015-0763Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers t...
CVE-2015-0762Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9)...
CVE-2015-0761Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement u...
CVE-2015-0760The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated ...
CVE-2015-4106QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might a...
CVE-2015-4105Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to ...
CVE-2015-4104Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users t...
CVE-2015-4103Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x...
CVE-2015-4038The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an i...
CVE-2015-0264Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2....
CVE-2015-0263XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel b...
CVE-2015-4162XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x...
CVE-2015-4161SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensi...
CVE-2015-4160SQL injection vulnerability in SAP ASE Database Platform allows remote attackers to execute arbitrary SQL commands via u...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now