2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0236 | — | — | 1.8% | Jan 29, 2015 | libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE fla... |
| CVE-2015-0586 | — | — | 2.3% | Jan 28, 2015 | The Network-Based Application Recognition (NBAR) protocol implementation in Cisco IOS 15.3(100)M and earlier on Cisco 29... |
| CVE-2015-0581 | — | — | 2.4% | Jan 28, 2015 | The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or c... |
| CVE-2015-0312 | — | — | 7.1% | Jan 28, 2015 | Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and... |
| CVE-2015-0235 | — | — | 94.9% | Jan 28, 2015 | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, ... |
| CVE-2015-1419 | — | — | 6.7% | Jan 28, 2015 | Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown ... |
| CVE-2015-1376 | — | — | 34.0% | Jan 28, 2015 | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot... |
| CVE-2015-1375 | — | — | 12.3% | Jan 28, 2015 | pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload... |
| CVE-2015-1182 | — | — | 3.2% | Jan 27, 2015 | The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not... |
| CVE-2015-1374 | — | — | 1.0% | Jan 27, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers ... |
| CVE-2015-1373 | — | — | 3.2% | Jan 27, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inje... |
| CVE-2015-1372 | — | — | 2.4% | Jan 27, 2015 | SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p... |
| CVE-2015-1371 | — | — | 8.1% | Jan 27, 2015 | Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code b... |
| CVE-2015-1370 | — | — | 2.1% | Jan 27, 2015 | Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site... |
| CVE-2015-1369 | — | — | 2.2% | Jan 27, 2015 | SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL c... |
| CVE-2015-1368 | — | — | 5.2% | Jan 27, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker... |
| CVE-2015-1367 | — | — | 2.1% | Jan 27, 2015 | SQL injection vulnerability in index.php in CatBot 0.4.2 allows remote attackers to execute arbitrary SQL commands via t... |
| CVE-2015-1366 | — | — | 6.1% | Jan 27, 2015 | Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress all... |
| CVE-2015-1365 | — | — | 13.4% | Jan 27, 2015 | Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem... |
| CVE-2015-1364 | — | — | 1.3% | Jan 27, 2015 | SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.... |
| CVE-2015-1363 | — | — | 1.9% | Jan 27, 2015 | Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrar... |
| CVE-2015-1362 | — | — | 8.3% | Jan 27, 2015 | Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co... |
| CVE-2015-1361 | — | — | 1.2% | Jan 27, 2015 | platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a varia... |
| CVE-2015-1360 | — | — | 1.3% | Jan 27, 2015 | Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-re... |
| CVE-2015-1359 | — | — | 1.5% | Jan 27, 2015 | Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allo... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now