2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0894 | — | — | 1.5% | Mar 7, 2015 | SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote att... |
| CVE-2015-1170 | — | — | 0.4% | Mar 6, 2015 | The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not pr... |
| CVE-2015-1637 | — | — | 13.2% | Mar 6, 2015 | Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP... |
| CVE-2015-1483 | — | — | 2.5% | Mar 6, 2015 | Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaSc... |
| CVE-2015-0661 | — | — | 1.0% | Mar 6, 2015 | The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon r... |
| CVE-2015-0659 | — | — | 1.1% | Mar 6, 2015 | The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS allows remote attackers to trigger self-refere... |
| CVE-2015-0657 | — | — | 1.2% | Mar 6, 2015 | Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka... |
| CVE-2015-0607 | — | — | 2.0% | Mar 6, 2015 | The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ ... |
| CVE-2015-0598 | — | — | 1.5% | Mar 6, 2015 | The RADIUS implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) v... |
| CVE-2015-2220 | — | — | 2.0% | Mar 5, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remot... |
| CVE-2015-2218 | — | — | 4.2% | Mar 5, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the Wo... |
| CVE-2015-2216 | — | — | 4.7% | Mar 5, 2015 | SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to exec... |
| CVE-2015-2215 | — | — | 1.5% | Mar 5, 2015 | Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal ... |
| CVE-2015-2214 | — | — | 2.4% | Mar 5, 2015 | NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netsho... |
| CVE-2015-0893 | — | — | 1.1% | Mar 5, 2015 | Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Relay Novel allows remote attackers to inject arbitrar... |
| CVE-2015-0892 | — | — | 1.1% | Mar 5, 2015 | Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Image Album allows remote attackers to inject arbitrar... |
| CVE-2015-0891 | — | — | 1.1% | Mar 5, 2015 | Cross-site scripting (XSS) vulnerability in Maroyaka CGI Maroyaka Simple Board allows remote attackers to inject arbitra... |
| CVE-2015-2209 | — | — | 1.4% | Mar 4, 2015 | DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php. |
| CVE-2015-0934 | — | — | 1.9% | Mar 4, 2015 | Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated user... |
| CVE-2015-0933 | — | — | 1.1% | Mar 4, 2015 | Absolute path traversal vulnerability in ShareLaTeX 0.1.3 and earlier, when the paranoid openin_any setting is omitted, ... |
| CVE-2015-0656 | — | — | 1.4% | Mar 4, 2015 | Cross-site scripting (XSS) vulnerability in the login page in Cisco Network Analysis Module (NAM) allows remote attacker... |
| CVE-2015-2199 | — | — | 2.6% | Mar 3, 2015 | Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote... |
| CVE-2015-2198 | — | — | 1.5% | Mar 3, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to i... |
| CVE-2015-2197 | — | — | 1.4% | Mar 3, 2015 | Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated ... |
| CVE-2015-2196 | — | — | 11.2% | Mar 3, 2015 | SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now