2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5377 | — | — | 14.9% | Mar 6, 2018 | Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the trans... |
| CVE-2015-7967 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories a... |
| CVE-2015-7966 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executab... |
| CVE-2015-7965 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executab... |
| CVE-2015-7964 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable mod... |
| CVE-2015-7963 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable m... |
| CVE-2015-7962 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and ex... |
| CVE-2015-7961 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and e... |
| CVE-2015-7598 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and e... |
| CVE-2015-7597 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules... |
| CVE-2015-7596 | — | — | 0.4% | Mar 2, 2018 | SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation director... |
| CVE-2015-0796 | MEDIUM | 6.3 | 0.9% | Mar 2, 2018 | In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could ... |
| CVE-2015-5079 | — | — | 17.6% | Feb 28, 2018 | Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit... |
| CVE-2015-4117 | — | — | 11.2% | Feb 28, 2018 | Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac... |
| CVE-2015-3898 | — | — | 6.1% | Feb 28, 2018 | Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arb... |
| CVE-2015-5725 | — | — | 2.4% | Feb 21, 2018 | SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote at... |
| CVE-2015-5316 | — | — | 3.4% | Feb 21, 2018 | The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is en... |
| CVE-2015-5315 | — | — | 2.6% | Feb 21, 2018 | The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembl... |
| CVE-2015-5314 | — | — | 2.3% | Feb 21, 2018 | The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassem... |
| CVE-2015-6569 | — | — | 2.0% | Feb 21, 2018 | Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to c... |
| CVE-2015-0203 | — | — | 8.9% | Feb 21, 2018 | The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon ... |
| CVE-2015-0262 | — | — | — | Feb 21, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-6544 | — | — | 5.6% | Feb 20, 2018 | Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows... |
| CVE-2015-9256 | — | — | 1.1% | Feb 20, 2018 | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore moun... |
| CVE-2015-9255 | — | — | 1.1% | Feb 20, 2018 | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, confi... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now