2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0903 | — | — | 3.2% | Apr 3, 2015 | Buffer overflow in Saitoh Kikaku Maruo Editor 8.51 and earlier allows remote attackers to execute arbitrary code via a c... |
| CVE-2015-0902 | — | — | 3.0% | Apr 3, 2015 | The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protectio... |
| CVE-2015-0684 | — | — | 1.4% | Apr 3, 2015 | SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allo... |
| CVE-2015-0683 | — | — | 1.3% | Apr 3, 2015 | Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via... |
| CVE-2015-0682 | — | — | 2.1% | Apr 3, 2015 | Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiti... |
| CVE-2015-0666 | HIGH | 7.5 | 40.6% | Apr 3, 2015 | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1... |
| CVE-2015-0687 | — | — | 1.0% | Apr 3, 2015 | The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual Switching System (V... |
| CVE-2015-0686 | — | — | 1.3% | Apr 3, 2015 | The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is ... |
| CVE-2015-0685 | — | — | 1.9% | Apr 3, 2015 | Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers... |
| CVE-2015-1234 | — | — | 1.5% | Apr 1, 2015 | Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote at... |
| CVE-2015-1233 | — | — | 5.3% | Apr 1, 2015 | Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, whic... |
| CVE-2015-2821 | — | — | 0.9% | Apr 1, 2015 | TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes i... |
| CVE-2015-2820 | — | — | 3.6% | Apr 1, 2015 | Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process ter... |
| CVE-2015-2819 | — | — | 2.4% | Apr 1, 2015 | SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, ak... |
| CVE-2015-2818 | — | — | 1.1% | Apr 1, 2015 | XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet se... |
| CVE-2015-2817 | — | — | 2.4% | Apr 1, 2015 | The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadPro... |
| CVE-2015-2816 | — | — | 2.6% | Apr 1, 2015 | The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspeci... |
| CVE-2015-2815 | — | — | 3.7% | Apr 1, 2015 | Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (... |
| CVE-2015-2814 | — | — | 1.2% | Apr 1, 2015 | SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not pr... |
| CVE-2015-2813 | — | — | 1.6% | Apr 1, 2015 | XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet serv... |
| CVE-2015-2812 | — | — | 2.5% | Apr 1, 2015 | XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remot... |
| CVE-2015-2811 | — | — | 2.4% | Apr 1, 2015 | XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attac... |
| CVE-2015-2756 | — | — | 0.5% | Apr 1, 2015 | QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow ... |
| CVE-2015-2755 | — | — | 3.9% | Apr 1, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for Wo... |
| CVE-2015-2752 | — | — | 0.5% | Apr 1, 2015 | The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preempti... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now