2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-4629Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN...
CVE-2015-4627SQL injection vulnerability in Pragyan CMS 3.0.
CVE-2015-4619Cross-site request forgery (CSRF) vulnerability in Spina before commit bfe44f289e336f80b6593032679300c493735e75.
CVE-2015-4085Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
CVE-2015-3991strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code...
CVE-2015-3314SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
CVE-2015-3313SQL injection vulnerability in WordPress Community Events plugin before 1.4.
CVE-2015-3222syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
CVE-2015-3169Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch.
CVE-2015-1590The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.
CVE-2015-3442Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API c...
CVE-2015-3250Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
CVE-2015-8316Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled a...
CVE-2015-7241XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
CVE-2015-7225Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successful...
CVE-2015-6250simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically gener...
CVE-2015-5959Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database passwor...
CVE-2015-5948Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exi...
CVE-2015-5705Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a c...
CVE-2015-5186Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
CVE-2015-3454TelescopeJS before 0.15 leaks user bcrypt password hashes in websocket messages, which might allow remote attackers to o...
CVE-2015-3450Heap-based buffer overflow in libaxl 0.6.9 allows attackers to cause a denial of service (memory corruption) or execute ...
CVE-2015-3162Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remot...
CVE-2015-3161The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals whe...
CVE-2015-3160XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now