2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-9550HIGH7.5An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. ...
CVE-2015-9548HIGH7.5An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory cons...
CVE-2015-9547HIGH7.5An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission...
CVE-2015-9545HIGH7.1An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not imp...
CVE-2015-9544HIGH7.1An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.j...
CVE-2015-8536HIGH8.8MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixe...
CVE-2015-8535HIGH7.8MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability ...
CVE-2015-8534HIGH7.8MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnera...
CVE-2015-7336HIGH7.5MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed ...
CVE-2015-7335HIGH7MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed...
CVE-2015-7334HIGH7.8MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnera...
CVE-2015-7333HIGH7.8MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnera...
CVE-2015-3641HIGH7.5bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a c...
CVE-2015-7342HIGH7.2JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Fi...
CVE-2015-7341HIGH8.8JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .p...
CVE-2015-7340HIGH7.2JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.
CVE-2015-7339HIGH8.8JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com...
CVE-2015-7338HIGH7.2SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude reques...
CVE-2015-1583HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentica...
CVE-2015-5686HIGH8.8Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request For...
CVE-2015-5201HIGH7.5VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x be...
CVE-2015-9542HIGH7.5add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is ...
CVE-2015-4411HIGH7.5The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attacker...
CVE-2015-4410HIGH7.5The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows re...
CVE-2015-7747HIGH8.8Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now