2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9271 | — | — | 4.3% | Oct 4, 2018 | The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execut... |
| CVE-2015-9270 | — | — | 1.0% | Oct 1, 2018 | XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter. |
| CVE-2015-9269 | — | — | 3.2% | Oct 1, 2018 | The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress a... |
| CVE-2015-9268 | HIGH | 7.8 | 1.5% | Oct 1, 2018 | Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, t... |
| CVE-2015-9267 | MEDIUM | 5.5 | 0.4% | Oct 1, 2018 | Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local user... |
| CVE-2015-8298 | — | — | 3.5% | Sep 24, 2018 | Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to exe... |
| CVE-2015-9266 | CRITICAL | 9.8 | 74.0% | Sep 5, 2018 | The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an... |
| CVE-2015-9265 | — | — | — | Aug 30, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14622. Reason: This candidate is a reservation... |
| CVE-2015-9264 | — | — | 1.9% | Aug 27, 2018 | Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation... |
| CVE-2015-9263 | — | — | 11.9% | Aug 27, 2018 | An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows ... |
| CVE-2015-5243 | — | — | 6.2% | Aug 20, 2018 | phpWhois allows remote attackers to execute arbitrary code via a crafted whois record. |
| CVE-2015-5160 | — | — | 0.4% | Aug 20, 2018 | libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which all... |
| CVE-2015-9262 | — | — | 5.9% | Aug 1, 2018 | _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or pot... |
| CVE-2015-9261 | MEDIUM | 5.5 | 2.4% | Jul 26, 2018 | huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and ... |
| CVE-2015-4968 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-1991 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-1990 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-0163 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-0155 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-0154 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-0230 | — | — | — | Jul 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2015-9260 | MEDIUM | 5.4 | 1.0% | Jul 5, 2018 | An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjec... |
| CVE-2015-4043 | — | — | 1.3% | Jun 19, 2018 | SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2015-4664 | — | — | 20.8% | Jun 18, 2018 | An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers t... |
| CVE-2015-9239 | HIGH | 7.5 | 1.2% | May 31, 2018 | ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now