2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-3148cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote a...
CVE-2015-3145The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which ...
CVE-2015-3144The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows r...
CVE-2015-3143cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to conne...
CVE-2015-0846django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote...
CVE-2015-0297Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers ...
CVE-2015-0911Directory traversal vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to read arbi...
CVE-2015-0910Cross-site scripting (XSS) vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to in...
CVE-2015-0707Cross-site scripting (XSS) vulnerability in Cisco FireSIGHT System Software 5.3.1.1 and 6.0.0 in FireSIGHT Management Ce...
CVE-2015-0706Open redirect vulnerability in Cisco FireSIGHT System Software 5.3.1.1, 5.3.1.2, and 6.0.0 in FireSIGHT Management Cente...
CVE-2015-3404The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authentic...
CVE-2015-1889The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass inte...
CVE-2015-1484Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and...
CVE-2015-3035HIGH7.5Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before ...
CVE-2015-0705Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified...
CVE-2015-0704Multiple cross-site request forgery (CSRF) vulnerabilities in API features in Cisco Unified MeetingPlace 8.6(1.9) allow ...
CVE-2015-3393Open redirect vulnerability in the Commerce WeDeal module before 7.x-1.3 for Drupal allows remote attackers to redirect ...
CVE-2015-3392Cross-site scripting (XSS) vulnerability in the Ajax Timeline module before 7.x-1.1 for Drupal allows remote authenticat...
CVE-2015-3391The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and...
CVE-2015-3390Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher module for Drupal allows remote authenticated use...
CVE-2015-3389Cross-site scripting (XSS) vulnerability in the Download counts report page in the Public Download Count module (pubdlcn...
CVE-2015-3388Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attack...
CVE-2015-3387Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy Tools module before 7.x-1.4 for Drupal allow remote ...
CVE-2015-3386Cross-site scripting (XSS) vulnerability in the Node Access Product module for Drupal allows remote authenticated users ...
CVE-2015-3385Cross-site scripting (XSS) vulnerability in the Taxonomy Path module before 7.x-1.2 for Drupal allows remote authenticat...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now