2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0821 | — | — | 2.3% | Feb 25, 2015 | Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScrip... |
| CVE-2015-0820 | — | — | 1.7% | Feb 25, 2015 | Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to ... |
| CVE-2015-0819 | — | — | 2.1% | Feb 25, 2015 | The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreg... |
| CVE-2015-2078 | — | — | 1.7% | Feb 24, 2015 | The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware A... |
| CVE-2015-2077 | — | — | 2.8% | Feb 24, 2015 | The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware A... |
| CVE-2015-2071 | — | — | 6.6% | Feb 24, 2015 | Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows r... |
| CVE-2015-2070 | — | — | 2.4% | Feb 24, 2015 | SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitra... |
| CVE-2015-2069 | — | — | 2.0% | Feb 24, 2015 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers t... |
| CVE-2015-2068 | — | — | 14.0% | Feb 24, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server a... |
| CVE-2015-2067 | — | — | 39.4% | Feb 24, 2015 | Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento... |
| CVE-2015-2066 | — | — | 1.3% | Feb 24, 2015 | SQL injection vulnerability in DLGuard 4.5 allows remote attackers to execute arbitrary SQL commands via the c parameter... |
| CVE-2015-2065 | — | — | 41.1% | Feb 24, 2015 | SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b... |
| CVE-2015-2064 | — | — | 1.2% | Feb 24, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in DLGuard 5, 4.6, and 4.5 allow remote attackers to inject arbitrar... |
| CVE-2015-1881 | — | — | 2.1% | Feb 24, 2015 | OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which al... |
| CVE-2015-1605 | — | — | 17.6% | Feb 24, 2015 | Multiple SQL injection vulnerabilities in Dell ScriptLogic Asset Manager (aka Quest Workspace Asset Manager) before 9.5 ... |
| CVE-2015-1572 | — | — | 0.6% | Feb 24, 2015 | Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execu... |
| CVE-2015-0555 | — | — | 6.4% | Feb 24, 2015 | Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote... |
| CVE-2015-0240 | — | — | 87.6% | Feb 24, 2015 | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1... |
| CVE-2015-2055 | — | — | 3.0% | Feb 23, 2015 | Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the ... |
| CVE-2015-2054 | — | — | 1.0% | Feb 23, 2015 | CRLF injection vulnerability in export.cfg in the web-based administrative console for Sierra Wireless AirCard 760S, 762... |
| CVE-2015-2053 | — | — | 1.5% | Feb 23, 2015 | The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and 5.0.0, when the "Accept connections only from the ePO serve... |
| CVE-2015-2052 | — | — | 5.2% | Feb 23, 2015 | Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote... |
| CVE-2015-2051 | HIGH | 8.8 | 97.1% | Feb 23, 2015 | The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute ar... |
| CVE-2015-2050 | — | — | 3.3% | Feb 23, 2015 | D-Link DAP-1320 Rev Ax with firmware before 1.21b05 allows attackers to execute arbitrary commands via unspecified vecto... |
| CVE-2015-2049 | — | — | 66.7% | Feb 23, 2015 | Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now