2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-0894SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote att...
CVE-2015-1170The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not pr...
CVE-2015-1637Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP...
CVE-2015-1483Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaSc...
CVE-2015-0661The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon r...
CVE-2015-0659The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS allows remote attackers to trigger self-refere...
CVE-2015-0657Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka...
CVE-2015-0607The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ ...
CVE-2015-0598The RADIUS implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) v...
CVE-2015-2220Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remot...
CVE-2015-2218Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the Wo...
CVE-2015-2216SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to exec...
CVE-2015-2215Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal ...
CVE-2015-2214NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netsho...
CVE-2015-0893Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Relay Novel allows remote attackers to inject arbitrar...
CVE-2015-0892Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Image Album allows remote attackers to inject arbitrar...
CVE-2015-0891Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Simple Board allows remote attackers to inject arbitra...
CVE-2015-2209DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
CVE-2015-0934Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated user...
CVE-2015-0933Absolute path traversal vulnerability in ShareLaTeX 0.1.3 and earlier, when the paranoid openin_any setting is omitted, ...
CVE-2015-0656Cross-site scripting (XSS) vulnerability in the login page in Cisco Network Analysis Module (NAM) allows remote attacker...
CVE-2015-2199Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote...
CVE-2015-2198Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to i...
CVE-2015-2197Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated ...
CVE-2015-2196SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now