2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0178 | — | — | 1.6% | Mar 18, 2015 | The Java overlay feature in IBM Bluemix Liberty before 1.13-20150209-1122 for Java does not properly support WAR applica... |
| CVE-2015-0149 | — | — | 0.9% | Mar 18, 2015 | The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and privat... |
| CVE-2015-0146 | — | — | 0.3% | Mar 18, 2015 | IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does... |
| CVE-2015-0132 | — | — | 1.4% | Mar 18, 2015 | The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requiremen... |
| CVE-2015-0128 | — | — | 1.1% | Mar 18, 2015 | Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.... |
| CVE-2015-0125 | — | — | 0.8% | Mar 18, 2015 | Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0... |
| CVE-2015-0124 | — | — | 1.4% | Mar 18, 2015 | Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.... |
| CVE-2015-2315 | — | — | 7.1% | Mar 17, 2015 | Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject... |
| CVE-2015-2314 | — | — | 7.1% | Mar 17, 2015 | SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary S... |
| CVE-2015-2293 | — | — | 1.5% | Mar 17, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SE... |
| CVE-2015-2292 | — | — | 5.8% | Mar 17, 2015 | Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be... |
| CVE-2015-0665 | — | — | 0.4% | Mar 17, 2015 | The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to ar... |
| CVE-2015-0663 | — | — | 0.3% | Mar 17, 2015 | Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messa... |
| CVE-2015-0662 | — | — | 0.4% | Mar 17, 2015 | Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privileges via crafted IPC me... |
| CVE-2015-0778 | — | — | 3.6% | Mar 16, 2015 | osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file. |
| CVE-2015-1593 | — | — | 3.7% | Mar 16, 2015 | The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the ... |
| CVE-2015-1421 | — | — | 9.9% | Mar 16, 2015 | Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8... |
| CVE-2015-1420 | — | — | 0.4% | Mar 16, 2015 | Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to b... |
| CVE-2015-0274 | — | — | 0.4% | Mar 16, 2015 | The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replace... |
| CVE-2015-2304 | — | — | 4.9% | Mar 15, 2015 | Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arb... |
| CVE-2015-2107 | — | — | 0.3% | Mar 14, 2015 | HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging ... |
| CVE-2015-0982 | — | — | 3.6% | Mar 14, 2015 | Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execut... |
| CVE-2015-0981 | — | — | 2.6% | Mar 14, 2015 | The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authenticat... |
| CVE-2015-0980 | — | — | 3.6% | Mar 14, 2015 | Format string vulnerability in BACnOPCServer.exe in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.... |
| CVE-2015-0979 | — | — | 4.6% | Mar 14, 2015 | Heap-based buffer overflow in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote a... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now