2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-4159SQL injection vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to execute arbitrary SQL...
CVE-2015-4158SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vector...
CVE-2015-4157SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, a...
CVE-2015-4156GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to...
CVE-2015-4155GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) --compress, allows local ...
CVE-2015-4094The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL ...
CVE-2015-4050FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.1...
CVE-2015-3982The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, wh...
CVE-2015-2944Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post befo...
CVE-2015-2282Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.c...
CVE-2015-2278The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, ...
CVE-2015-1945Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0...
CVE-2015-0850The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parame...
CVE-2015-0759Cross-site request forgery (CSRF) vulnerability in Cisco Headend Digital Broadband Delivery System allows remote attacke...
CVE-2015-3181files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not ...
CVE-2015-3180lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows re...
CVE-2015-3179login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote...
CVE-2015-3178Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2...
CVE-2015-3177Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-...
CVE-2015-3176The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, ...
CVE-2015-3175Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x befor...
CVE-2015-3174mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not...
CVE-2015-2273Cross-site scripting (XSS) vulnerability in mod/quiz/report/statistics/statistics_question_table.php in Moodle through 2...
CVE-2015-2272login/token.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote au...
CVE-2015-2271tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider t...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now