2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0755 | — | — | 0.3% | May 29, 2015 | The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4... |
| CVE-2015-0754 | — | — | 1.9% | May 29, 2015 | Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CP... |
| CVE-2015-0753 | — | — | 1.8% | May 29, 2015 | SQL injection vulnerability in Cisco Unified Email Interaction Manager (EIM) and Unified Web Interaction Manager (WIM) 9... |
| CVE-2015-0752 | — | — | 1.5% | May 29, 2015 | Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote att... |
| CVE-2015-0751 | — | — | 1.9% | May 29, 2015 | Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to... |
| CVE-2015-0200 | — | — | 0.4% | May 29, 2015 | IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database i... |
| CVE-2015-4137 | — | — | 2.4% | May 29, 2015 | SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL ... |
| CVE-2015-3904 | — | — | 2.6% | May 29, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php in the Roomcloud plugin before 1.3 for WordPress al... |
| CVE-2015-4135 | — | — | 1.9% | May 28, 2015 | Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web scri... |
| CVE-2015-4134 | — | — | 2.1% | May 28, 2015 | Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites ... |
| CVE-2015-4133 | — | — | 61.3% | May 28, 2015 | Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f... |
| CVE-2015-4132 | — | — | 0.6% | May 28, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow... |
| CVE-2015-4127 | — | — | 7.4% | May 28, 2015 | Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers t... |
| CVE-2015-4084 | — | — | 4.5% | May 28, 2015 | Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject ... |
| CVE-2015-3165 | — | — | 8.6% | May 28, 2015 | Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and... |
| CVE-2015-1551 | — | — | 1.0% | May 28, 2015 | Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administr... |
| CVE-2015-1550 | — | — | 2.0% | May 28, 2015 | Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administr... |
| CVE-2015-1392 | — | — | 0.8% | May 28, 2015 | Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote admin... |
| CVE-2015-1389 | — | — | 6.8% | May 28, 2015 | Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote at... |
| CVE-2015-1157 | — | — | 5.5% | May 28, 2015 | CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disrupt... |
| CVE-2015-4066 | — | — | 4.2% | May 27, 2015 | Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem... |
| CVE-2015-4065 | — | — | 3.9% | May 27, 2015 | Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before ... |
| CVE-2015-4064 | — | — | 3.7% | May 27, 2015 | SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo... |
| CVE-2015-4063 | — | — | 6.1% | May 27, 2015 | Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPres... |
| CVE-2015-4062 | — | — | 9.1% | May 27, 2015 | SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remo... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now