2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-3148 | — | — | 17.9% | Apr 24, 2015 | cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote a... |
| CVE-2015-3145 | — | — | 37.6% | Apr 24, 2015 | The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which ... |
| CVE-2015-3144 | — | — | 11.0% | Apr 24, 2015 | The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows r... |
| CVE-2015-3143 | — | — | 16.2% | Apr 24, 2015 | cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to conne... |
| CVE-2015-0846 | — | — | 1.8% | Apr 24, 2015 | django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote... |
| CVE-2015-0297 | — | — | 2.2% | Apr 24, 2015 | Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers ... |
| CVE-2015-0911 | — | — | 1.9% | Apr 24, 2015 | Directory traversal vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to read arbi... |
| CVE-2015-0910 | — | — | 1.1% | Apr 24, 2015 | Cross-site scripting (XSS) vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to in... |
| CVE-2015-0707 | — | — | 0.8% | Apr 23, 2015 | Cross-site scripting (XSS) vulnerability in Cisco FireSIGHT System Software 5.3.1.1 and 6.0.0 in FireSIGHT Management Ce... |
| CVE-2015-0706 | — | — | 1.1% | Apr 23, 2015 | Open redirect vulnerability in Cisco FireSIGHT System Software 5.3.1.1, 5.3.1.2, and 6.0.0 in FireSIGHT Management Cente... |
| CVE-2015-3404 | — | — | 0.7% | Apr 22, 2015 | The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authentic... |
| CVE-2015-1889 | — | — | 1.6% | Apr 22, 2015 | The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass inte... |
| CVE-2015-1484 | — | — | 0.4% | Apr 22, 2015 | Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and... |
| CVE-2015-3035 | HIGH | 7.5 | 83.8% | Apr 22, 2015 | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before ... |
| CVE-2015-0705 | — | — | 1.3% | Apr 22, 2015 | Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified... |
| CVE-2015-0704 | — | — | 1.0% | Apr 22, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in API features in Cisco Unified MeetingPlace 8.6(1.9) allow ... |
| CVE-2015-3393 | — | — | 1.2% | Apr 21, 2015 | Open redirect vulnerability in the Commerce WeDeal module before 7.x-1.3 for Drupal allows remote attackers to redirect ... |
| CVE-2015-3392 | — | — | 1.0% | Apr 21, 2015 | Cross-site scripting (XSS) vulnerability in the Ajax Timeline module before 7.x-1.1 for Drupal allows remote authenticat... |
| CVE-2015-3391 | — | — | 1.4% | Apr 21, 2015 | The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and... |
| CVE-2015-3390 | — | — | 1.0% | Apr 21, 2015 | Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher module for Drupal allows remote authenticated use... |
| CVE-2015-3389 | — | — | 1.0% | Apr 21, 2015 | Cross-site scripting (XSS) vulnerability in the Download counts report page in the Public Download Count module (pubdlcn... |
| CVE-2015-3388 | — | — | 0.6% | Apr 21, 2015 | Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attack... |
| CVE-2015-3387 | — | — | 1.0% | Apr 21, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy Tools module before 7.x-1.4 for Drupal allow remote ... |
| CVE-2015-3386 | — | — | 1.0% | Apr 21, 2015 | Cross-site scripting (XSS) vulnerability in the Node Access Product module for Drupal allows remote authenticated users ... |
| CVE-2015-3385 | — | — | 1.0% | Apr 21, 2015 | Cross-site scripting (XSS) vulnerability in the Taxonomy Path module before 7.x-1.2 for Drupal allows remote authenticat... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now