2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0198 | — | — | 4.2% | Mar 24, 2015 | IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain ciph... |
| CVE-2015-0197 | — | — | 0.5% | Mar 24, 2015 | IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local us... |
| CVE-2015-0158 | — | — | 1.8% | Mar 24, 2015 | Cross-site scripting (XSS) vulnerability in the Coach NG framework in IBM Business Process Manager (BPM) 8.0 through 8.0... |
| CVE-2015-0818 | — | — | 3.1% | Mar 24, 2015 | Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to byp... |
| CVE-2015-0817 | — | — | 3.7% | Mar 24, 2015 | The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 ... |
| CVE-2015-0527 | — | — | 0.5% | Mar 24, 2015 | EMC Documentum xCelerated Management System (xMS) 1.1 before P14 stores cleartext Windows Service credentials in a batch... |
| CVE-2015-0137 | — | — | 0.7% | Mar 24, 2015 | IBM PowerVC Standard 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 validates Hardware Management Console (HMC) certifi... |
| CVE-2015-0136 | — | — | 0.4% | Mar 24, 2015 | powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command ... |
| CVE-2015-0106 | — | — | 1.3% | Mar 24, 2015 | Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.... |
| CVE-2015-0105 | — | — | 1.7% | Mar 24, 2015 | Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3... |
| CVE-2015-0103 | — | — | 1.0% | Mar 24, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Process Portal in IBM Business Process Manager (BPM) 8.0 thro... |
| CVE-2015-2681 | — | — | 1.9% | Mar 23, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allow r... |
| CVE-2015-2680 | — | — | 3.9% | Mar 23, 2015 | Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th... |
| CVE-2015-2679 | — | — | 5.6% | Mar 23, 2015 | Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary S... |
| CVE-2015-2678 | — | — | 5.4% | Mar 23, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject... |
| CVE-2015-2677 | — | — | 1.5% | Mar 23, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in ocPortal before 9.0.17 allow remote authenticated users to inject... |
| CVE-2015-2676 | — | — | 1.1% | Mar 23, 2015 | Cross-site request forgery (CSRF) vulnerability in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allows remo... |
| CVE-2015-2289 | — | — | 1.7% | Mar 23, 2015 | Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows remote a... |
| CVE-2015-0941 | — | — | 1.4% | Mar 22, 2015 | The Inetc plugin for Nullsoft Scriptable Install System (NSIS), as used in CERT/CC Failure Observation Engine (FOE) and ... |
| CVE-2015-0898 | — | — | 2.5% | Mar 21, 2015 | futomi CGI Cafe MP Form Mail CGI eCommerce before 2.0.12 on Windows allows remote attackers to execute arbitrary Perl co... |
| CVE-2015-0670 | — | — | 1.8% | Mar 21, 2015 | The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support au... |
| CVE-2015-0669 | — | — | 1.7% | Mar 21, 2015 | The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to ... |
| CVE-2015-2564 | — | — | 3.1% | Mar 20, 2015 | SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to ... |
| CVE-2015-2563 | — | — | 2.2% | Mar 20, 2015 | SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9 and 1.2.3 allows remote attackers to execute arb... |
| CVE-2015-2562 | — | — | 38.9% | Mar 20, 2015 | Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now