2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-0903Buffer overflow in Saitoh Kikaku Maruo Editor 8.51 and earlier allows remote attackers to execute arbitrary code via a c...
CVE-2015-0902The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protectio...
CVE-2015-0684SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allo...
CVE-2015-0683Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via...
CVE-2015-0682Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiti...
CVE-2015-0666HIGH7.5Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1...
CVE-2015-0687The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual Switching System (V...
CVE-2015-0686The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is ...
CVE-2015-0685Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers...
CVE-2015-1234Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote at...
CVE-2015-1233Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, whic...
CVE-2015-2821TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes i...
CVE-2015-2820Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process ter...
CVE-2015-2819SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, ak...
CVE-2015-2818XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet se...
CVE-2015-2817The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadPro...
CVE-2015-2816The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspeci...
CVE-2015-2815Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (...
CVE-2015-2814SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not pr...
CVE-2015-2813XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet serv...
CVE-2015-2812XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remot...
CVE-2015-2811XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attac...
CVE-2015-2756QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow ...
CVE-2015-2755Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for Wo...
CVE-2015-2752The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preempti...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now