2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1641 | HIGH | 7.8 | 97.3% | Apr 14, 2015 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Comp... |
| CVE-2015-1640 | — | — | 8.9% | Apr 14, 2015 | Cross-site scripting (XSS) vulnerability in Microsoft Project Server 2010 SP2 and 2013 SP1 allows remote attackers to in... |
| CVE-2015-1639 | — | — | 9.5% | Apr 14, 2015 | Cross-site scripting (XSS) vulnerability in Microsoft Office for Mac 2011 allows remote attackers to inject arbitrary we... |
| CVE-2015-1638 | — | — | 12.8% | Apr 14, 2015 | Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff act... |
| CVE-2015-1635 | CRITICAL | 9.8 | 100.0% | Apr 14, 2015 | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an... |
| CVE-2015-0098 | — | — | 1.6% | Apr 14, 2015 | Task Scheduler in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges by trigge... |
| CVE-2015-3293 | — | — | 1.0% | Apr 14, 2015 | FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" ... |
| CVE-2015-2831 | — | — | 0.5% | Apr 14, 2015 | Buffer overflow in das_watchdog 0.9.0 allows local users to execute arbitrary code with root privileges via a large stri... |
| CVE-2015-2788 | — | — | 4.2% | Apr 14, 2015 | Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remot... |
| CVE-2015-0844 | — | — | 2.3% | Apr 14, 2015 | The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbi... |
| CVE-2015-2926 | — | — | 1.9% | Apr 14, 2015 | Cross-site scripting (XSS) vulnerability in Php/stats/statsRecent.inc.php in phpTrafficA 2.3 and earlier allows remote a... |
| CVE-2015-2781 | — | — | 1.9% | Apr 14, 2015 | Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows ... |
| CVE-2015-2223 | — | — | 4.0% | Apr 14, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks ... |
| CVE-2015-2942 | — | — | 2.8% | Apr 13, 2015 | MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows remote attackers to caus... |
| CVE-2015-2941 | — | — | 2.1% | Apr 13, 2015 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when... |
| CVE-2015-2940 | — | — | 1.1% | Apr 13, 2015 | Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hija... |
| CVE-2015-2939 | — | — | 2.1% | Apr 13, 2015 | Cross-site scripting (XSS) vulnerability in the Scribunto extension for MediaWiki allows remote attackers to inject arbi... |
| CVE-2015-2938 | — | — | 2.1% | Apr 13, 2015 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allow... |
| CVE-2015-2937 | — | — | 2.7% | Apr 13, 2015 | MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM or Zend PHP, allows remote attac... |
| CVE-2015-2936 | — | — | 2.7% | Apr 13, 2015 | MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of ser... |
| CVE-2015-2935 | — | — | 2.5% | Apr 13, 2015 | MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filteri... |
| CVE-2015-2934 | — | — | 2.1% | Apr 13, 2015 | MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interprete... |
| CVE-2015-2933 | — | — | 2.1% | Apr 13, 2015 | Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x b... |
| CVE-2015-2932 | — | — | 2.1% | Apr 13, 2015 | Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remo... |
| CVE-2015-2931 | — | — | 2.2% | Apr 13, 2015 | Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, an... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now