2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-4627——SQL injection vulnerability in Pragyan CMS 3.0.
CVE-2015-4619——Cross-site request forgery (CSRF) vulnerability in Spina before commit bfe44f289e336f80b6593032679300c493735e75.
CVE-2015-4085——Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
CVE-2015-3991——strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code...
CVE-2015-3314——SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
CVE-2015-3313——SQL injection vulnerability in WordPress Community Events plugin before 1.4.
CVE-2015-3222——syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
CVE-2015-3169——Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch.
CVE-2015-1590——The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.
CVE-2015-3442——Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API c...
CVE-2015-3250——Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
CVE-2015-8316——Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled a...
CVE-2015-7241——XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
CVE-2015-7225——Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successful...
CVE-2015-6250——simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically gener...
CVE-2015-5959——Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database passwor...
CVE-2015-5948——Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exi...
CVE-2015-5705——Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a c...
CVE-2015-5186——Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
CVE-2015-3454——TelescopeJS before 0.15 leaks user bcrypt password hashes in websocket messages, which might allow remote attackers to o...
CVE-2015-3450——Heap-based buffer overflow in libaxl 0.6.9 allows attackers to cause a denial of service (memory corruption) or execute ...
CVE-2015-3162——Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remot...
CVE-2015-3161——The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals whe...
CVE-2015-3160——XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to...
CVE-2015-2943——Honda Moto LINC 1.6.1 does not verify SSL certificates.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now