2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-0717Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an u...
CVE-2015-0736Cross-site request forgery (CSRF) vulnerability in Cisco MediaSense 10.5(1) and earlier allows remote attackers to hijac...
CVE-2015-0731The ISDN implementation in Cisco IOS 15.3S allows remote attackers to cause a denial of service (device reload) via malf...
CVE-2015-2810Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP befo...
CVE-2015-3989Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary...
CVE-2015-3325SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to...
CVE-2015-2250Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary...
CVE-2015-0734Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Email Security Appliance (ESA) 8.5.6-106 allow remote a...
CVE-2015-0728Cross-site scripting (XSS) vulnerability in Cisco Access Control Server (ACS) 5.5(0.1) allows remote attackers to inject...
CVE-2015-0727Cross-site scripting (XSS) vulnerability in the HTTP module in Cisco Security Manager (CSM) 4.7(0)SP1(1) allows remote a...
CVE-2015-0724Multiple cross-site scripting (XSS) vulnerabilities in dncs 7.0.0.12 in Cisco Headend Digital Broadband Delivery System ...
CVE-2015-0634Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.99...
CVE-2015-3987Multiple unquoted Windows search path vulnerabilities in the (1) Client Management and (2) Gateway in McAfee ePO Deep Co...
CVE-2015-3986Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPr...
CVE-2015-3983The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes ...
CVE-2015-3427Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, wh...
CVE-2015-3301Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce ...
CVE-2015-3300Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional Wo...
CVE-2015-1848The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which ma...
CVE-2015-0971The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related...
CVE-2015-2720The update implementation in Mozilla Firefox before 38.0 on Windows does not ensure that the pathname for updater.exe co...
CVE-2015-2718The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote attackers to bypass the Same Origin Policy and ob...
CVE-2015-2717Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or c...
CVE-2015-2716Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 3...
CVE-2015-2715Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attac...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now