2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-3639phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to exec...
CVE-2015-3638phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary ...
CVE-2015-3421The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables...
CVE-2015-3198The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the ...
CVE-2015-3170selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH logi...
CVE-2015-1323The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0u...
CVE-2015-5152Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to t...
CVE-2015-0249The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for ...
CVE-2015-3297Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to rea...
CVE-2015-9105Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, ...
CVE-2015-9104Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows ...
CVE-2015-9103Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authentic...
CVE-2015-9102Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-296...
CVE-2015-8697stalin 0.11-5 allows local users to write to arbitrary files.
CVE-2015-7898Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7895Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7781ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
CVE-2015-7780Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
CVE-2015-7582Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-2100. Reason: This candidate is a reservation ...
CVE-2015-5378Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwa...
CVE-2015-5180res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereferen...
CVE-2015-3840The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter se...
CVE-2015-2245Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).
CVE-2015-1795Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
CVE-2015-1778The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authe...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now