2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1604 | — | — | 4.1% | Feb 19, 2015 | Unrestricted file upload vulnerability in asys/site/files.php in Adminsystems CMS before 4.0.2 allows remote authenticat... |
| CVE-2015-1603 | — | — | 2.5% | Feb 19, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems CMS before 4.0.2 allow remote attackers to inject ar... |
| CVE-2015-1592 | — | — | 75.0% | Feb 19, 2015 | Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use ... |
| CVE-2015-1587 | — | — | 44.2% | Feb 19, 2015 | Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earl... |
| CVE-2015-1585 | — | — | 1.1% | Feb 19, 2015 | Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request wi... |
| CVE-2015-1515 | — | — | 1.0% | Feb 19, 2015 | The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memo... |
| CVE-2015-1197 | — | — | 2.9% | Feb 19, 2015 | cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink a... |
| CVE-2015-1349 | — | — | 22.2% | Feb 19, 2015 | named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the manage... |
| CVE-2015-0626 | — | — | 1.1% | Feb 19, 2015 | The SOAP interface in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to obtain access to system-manag... |
| CVE-2015-0623 | — | — | 0.9% | Feb 19, 2015 | Cross-site scripting (XSS) vulnerability in the Administrator report page on Cisco Web Security Appliance (WSA) devices ... |
| CVE-2015-0622 | — | — | 1.4% | Feb 19, 2015 | The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote a... |
| CVE-2015-1358 | — | — | 2.7% | Feb 18, 2015 | The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens S... |
| CVE-2015-1356 | — | — | 0.5% | Feb 18, 2015 | Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields tha... |
| CVE-2015-1355 | — | — | 0.4% | Feb 18, 2015 | Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local u... |
| CVE-2015-0621 | — | — | 1.8% | Feb 18, 2015 | Cisco TelePresence MCU devices with software 4.5(1.45) allow remote attackers to cause a denial of service (device reloa... |
| CVE-2015-0620 | — | — | 1.3% | Feb 18, 2015 | The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entit... |
| CVE-2015-0617 | — | — | 1.6% | Feb 18, 2015 | Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices allow remote attackers to cause a denial of service (... |
| CVE-2015-0109 | — | — | 0.8% | Feb 18, 2015 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management... |
| CVE-2015-0108 | — | — | 0.9% | Feb 18, 2015 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management... |
| CVE-2015-1621 | — | — | 0.9% | Feb 17, 2015 | Cross-site scripting (XSS) vulnerability in the Webform prepopulate block module before 7.x-3.1 for Drupal allows remote... |
| CVE-2015-1619 | — | — | 1.1% | Feb 17, 2015 | Cross-site scripting (XSS) vulnerability in the Secure Web Mail Client user interface in McAfee Email Gateway (MEG) 7.6.... |
| CVE-2015-1618 | — | — | 1.3% | Feb 17, 2015 | The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to obt... |
| CVE-2015-1617 | — | — | 1.1% | Feb 17, 2015 | Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.... |
| CVE-2015-1616 | — | — | 1.4% | Feb 17, 2015 | SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows re... |
| CVE-2015-1494 | — | — | 6.4% | Feb 17, 2015 | The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now