2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0767 | — | — | 0.4% | Jun 7, 2015 | Cisco Edge 300 software 1.0 and 1.1 on Edge 340 devices allows local users to obtain root privileges via unspecified com... |
| CVE-2015-0112 | — | — | 1.0% | Jun 7, 2015 | Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1, 4.x before 4.0.7 IF5... |
| CVE-2015-3950 | — | — | 0.6% | Jun 5, 2015 | Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hij... |
| CVE-2015-2951 | — | — | 3.8% | Jun 5, 2015 | JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens. |
| CVE-2015-2950 | — | — | 1.9% | Jun 5, 2015 | Directory traversal vulnerability in the Brandon Bowles Open Explorer application before 0.254 Beta for Android allows r... |
| CVE-2015-2124 | — | — | 0.6% | Jun 5, 2015 | Unspecified vulnerability in Easy Setup Wizard in HP ThinPro Linux 4.1 through 5.1 and Smart Zero Core 4.3 and 4.4 allow... |
| CVE-2015-1000 | — | — | 3.3% | Jun 5, 2015 | Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX c... |
| CVE-2015-0541 | — | — | 1.0% | Jun 5, 2015 | Cross-site request forgery (CSRF) vulnerability in EMC RSA Web Threat Detection before 5.1 allows remote attackers to hi... |
| CVE-2015-0766 | — | — | 1.5% | Jun 4, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in the Management Center compone... |
| CVE-2015-0765 | — | — | 2.0% | Jun 4, 2015 | Cisco ONS 15454 System Software 10.30 and 10.301 allows remote attackers to cause a denial of service (tNetTask CPU cons... |
| CVE-2015-0764 | — | — | 1.9% | Jun 4, 2015 | Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka ... |
| CVE-2015-0763 | — | — | 1.9% | Jun 4, 2015 | Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers t... |
| CVE-2015-0762 | — | — | 1.6% | Jun 4, 2015 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9)... |
| CVE-2015-0761 | — | — | 0.4% | Jun 4, 2015 | Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement u... |
| CVE-2015-0760 | — | — | 2.0% | Jun 4, 2015 | The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated ... |
| CVE-2015-4106 | — | — | 0.5% | Jun 3, 2015 | QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might a... |
| CVE-2015-4105 | — | — | 0.5% | Jun 3, 2015 | Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to ... |
| CVE-2015-4104 | — | — | 3.4% | Jun 3, 2015 | Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users t... |
| CVE-2015-4103 | — | — | 0.4% | Jun 3, 2015 | Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x... |
| CVE-2015-4038 | — | — | 8.3% | Jun 3, 2015 | The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an i... |
| CVE-2015-0264 | — | — | 7.1% | Jun 3, 2015 | Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.... |
| CVE-2015-0263 | — | — | 7.5% | Jun 3, 2015 | XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel b... |
| CVE-2015-4162 | — | — | 1.0% | Jun 2, 2015 | XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x... |
| CVE-2015-4161 | — | — | 1.4% | Jun 2, 2015 | SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensi... |
| CVE-2015-4160 | — | — | 1.3% | Jun 2, 2015 | SQL injection vulnerability in SAP ASE Database Platform allows remote attackers to execute arbitrary SQL commands via u... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now