2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2048 | — | — | 0.9% | Feb 23, 2015 | Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attacker... |
| CVE-2015-2047 | — | — | 1.5% | Feb 23, 2015 | The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.1... |
| CVE-2015-1589 | — | — | 1.8% | Feb 23, 2015 | Directory traversal vulnerability in arCHMage 0.2.4 allows remote attackers to write to arbitrary files via a .. (dot do... |
| CVE-2015-1426 | — | — | 0.4% | Feb 23, 2015 | Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by readi... |
| CVE-2015-1315 | — | — | 4.9% | Feb 23, 2015 | Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to exec... |
| CVE-2015-0631 | — | — | 1.2% | Feb 21, 2015 | Race condition in the SSL implementation on Cisco Intrusion Prevention System (IPS) devices allows remote attackers to c... |
| CVE-2015-0624 | — | — | 2.2% | Feb 21, 2015 | The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and W... |
| CVE-2015-0618 | — | — | 2.3% | Feb 21, 2015 | Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Carrier Routing Sys... |
| CVE-2015-0331 | — | — | 6.1% | Feb 21, 2015 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows ... |
| CVE-2015-2010 | — | — | — | Feb 20, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-0010. Reason: This candidate is a duplicate of... |
| CVE-2015-2040 | — | — | 1.6% | Feb 20, 2015 | Cross-site scripting (XSS) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plug... |
| CVE-2015-2039 | — | — | 1.2% | Feb 20, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Acobot Live Chat & Contact Form plugin 2.0 for WordPre... |
| CVE-2015-2035 | — | — | 1.8% | Feb 20, 2015 | SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute... |
| CVE-2015-2034 | — | — | 2.2% | Feb 20, 2015 | Cross-site scripting (XSS) vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote attackers to... |
| CVE-2015-1517 | — | — | 2.7% | Feb 20, 2015 | SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to... |
| CVE-2015-0167 | — | — | 1.4% | Feb 20, 2015 | Cross-site scripting (XSS) vulnerability in textAngular-sanitize.js in textAngular before 1.3.7 allows remote attackers ... |
| CVE-2015-2033 | — | — | 3.0% | Feb 20, 2015 | Anyterm Daemon in Infoblox Network Automation NetMRI before NETMRI-23483 allows remote attackers to execute arbitrary co... |
| CVE-2015-0881 | — | — | 4.5% | Feb 20, 2015 | CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct ... |
| CVE-2015-0880 | — | — | 2.7% | Feb 20, 2015 | Buffer overflow in CREAR AL-Mail32 before 1.13d allows remote attackers to execute arbitrary code via a long filename of... |
| CVE-2015-0879 | — | — | 1.3% | Feb 20, 2015 | CREAR AL-Mail32 before 1.13d allows remote attackers to cause a denial of service (application crash) via a (1) CON, (2)... |
| CVE-2015-0878 | — | — | 1.6% | Feb 20, 2015 | Directory traversal vulnerability in CREAR AL-Mail32 before 1.13d allows remote attackers to write to arbitrary files vi... |
| CVE-2015-0628 | — | — | 1.2% | Feb 20, 2015 | The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restr... |
| CVE-2015-0584 | — | — | 0.3% | Feb 20, 2015 | The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX6... |
| CVE-2015-1879 | — | — | 2.1% | Feb 19, 2015 | Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote att... |
| CVE-2015-1614 | — | — | 1.2% | Feb 19, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow rem... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now