2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2943 | — | — | 0.7% | Sep 6, 2017 | Honda Moto LINC 1.6.1 does not verify SSL certificates. |
| CVE-2015-2210 | — | — | 0.6% | Sep 6, 2017 | The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injectin... |
| CVE-2015-7746 | — | — | 1.6% | Sep 1, 2017 | NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtai... |
| CVE-2015-7711 | — | — | 1.6% | Aug 31, 2017 | Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject ar... |
| CVE-2015-7700 | — | — | 2.2% | Aug 31, 2017 | Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspe... |
| CVE-2015-5695 | — | — | 2.1% | Aug 31, 2017 | Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records p... |
| CVE-2015-8334 | — | — | 0.9% | Aug 29, 2017 | SQL injection vulnerability in the Operation and Maintenance Unit (OMU) in Huawei VCN500 before V100R002C00SPC201 allows... |
| CVE-2015-8299 | — | — | 6.2% | Aug 29, 2017 | Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute ... |
| CVE-2015-7517 | — | — | 4.2% | Aug 29, 2017 | Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote ... |
| CVE-2015-7255 | — | — | 2.0% | Aug 29, 2017 | ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certifica... |
| CVE-2015-6942 | — | — | 0.9% | Aug 29, 2017 | Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2015-6588 | — | — | 1.2% | Aug 29, 2017 | Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to in... |
| CVE-2015-5209 | — | — | 9.1% | Aug 29, 2017 | Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect... |
| CVE-2015-4649 | — | — | 1.7% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t... |
| CVE-2015-3657 | — | — | 1.1% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level admi... |
| CVE-2015-3656 | — | — | 1.1% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level admi... |
| CVE-2015-3654 | — | — | 1.7% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t... |
| CVE-2015-3653 | — | — | 2.3% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t... |
| CVE-2015-0234 | — | — | 1.3% | Aug 29, 2017 | Multiple temporary file creation vulnerabilities in pki-core 10.2.0. |
| CVE-2015-8332 | — | — | 1.0% | Aug 28, 2017 | Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities an... |
| CVE-2015-8300 | — | — | 0.6% | Aug 28, 2017 | Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\poly... |
| CVE-2015-1600 | — | — | 2.8% | Aug 28, 2017 | Information disclosure vulnerability in Netatmo Indoor Module firmware 100 and earlier. |
| CVE-2015-1554 | — | — | 1.5% | Aug 28, 2017 | kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash). |
| CVE-2015-0233 | — | — | 0.4% | Aug 28, 2017 | Multiple insecure Temporary File vulnerabilities in 389 Administration Server before 1.1.38. |
| CVE-2015-3976 | — | — | 1.2% | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multili... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now