2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-0363 | — | — | 1.3% | Jan 21, 2015 | Unspecified vulnerability in the Siebel Core EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authentica... |
| CVE-2015-0362 | — | — | 1.4% | Jan 21, 2015 | Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7 al... |
| CVE-2015-1048 | — | — | 1.5% | Jan 21, 2015 | Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1... |
| CVE-2015-1204 | — | — | 2.3% | Jan 21, 2015 | Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.2 for Wo... |
| CVE-2015-1164 | — | — | 2.6% | Jan 21, 2015 | Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote... |
| CVE-2015-1032 | — | — | 1.9% | Jan 21, 2015 | Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when using kiwix-serve, allows remote attackers to injec... |
| CVE-2015-1028 | — | — | 2.8% | Jan 21, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo... |
| CVE-2015-0553 | — | — | 2.0% | Jan 21, 2015 | Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to ... |
| CVE-2015-0867 | — | — | 1.9% | Jan 21, 2015 | Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arb... |
| CVE-2015-0516 | — | — | 7.4% | Jan 21, 2015 | Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authen... |
| CVE-2015-0515 | — | — | 2.9% | Jan 21, 2015 | Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote a... |
| CVE-2015-0514 | — | — | 7.6% | Jan 21, 2015 | EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen... |
| CVE-2015-0513 | — | — | 1.6% | Jan 21, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) befo... |
| CVE-2015-1201 | — | — | 1.3% | Jan 20, 2015 | Privoxy before 3.0.22 allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified... |
| CVE-2015-1030 | — | — | 2.4% | Jan 20, 2015 | Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a... |
| CVE-2015-0973 | HIGH | 8.8 | 4.3% | Jan 18, 2015 | Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows ... |
| CVE-2015-0862 | — | — | 1.2% | Jan 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.... |
| CVE-2015-0924 | — | — | 1.4% | Jan 17, 2015 | Ceragon FibeAir IP-10 bridges have a default password for the root account, which makes it easier for remote attackers t... |
| CVE-2015-0590 | — | — | 2.0% | Jan 17, 2015 | Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sens... |
| CVE-2015-1029 | — | — | 1.6% | Jan 16, 2015 | The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows re... |
| CVE-2015-0222 | — | — | 2.7% | Jan 16, 2015 | ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, ... |
| CVE-2015-0221 | — | — | 4.3% | Jan 16, 2015 | The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an e... |
| CVE-2015-0220 | — | — | 3.0% | Jan 16, 2015 | The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not ... |
| CVE-2015-0219 | — | — | 6.8% | Jan 16, 2015 | Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using... |
| CVE-2015-1060 | — | — | 4.4% | Jan 16, 2015 | Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now