2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-9254Datto ALTO and SIRIS devices have a default VNC password.
CVE-2015-2081Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.
CVE-2015-9253An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master proce...
CVE-2015-2324Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allo...
CVE-2015-9252An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral...
CVE-2015-1862The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot...
CVE-2015-2329Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to...
CVE-2015-4400Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless networ...
CVE-2015-3619Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! a...
CVE-2015-3618Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attack...
CVE-2015-5674The routed daemon in FreeBSD 9.3 before 9.3-RELEASE-p22, 10.2-RC2 before 10.2-RC2-p1, 10.2-RC1 before 10.2-RC1-p2, 10.2 ...
CVE-2015-4461Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensiti...
CVE-2015-4412BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attacker...
CVE-2015-4179Multiple cross-site request forgery (CSRF) vulnerabilities in the Codestyling Localization plugin 1.99.30 and earlier fo...
CVE-2015-1418The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 b...
CVE-2015-1416Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEAS...
CVE-2015-2186The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use ...
CVE-2015-2796Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject ar...
CVE-2015-2204Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access ...
CVE-2015-2203Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive sett...
CVE-2015-1142857On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF...
CVE-2015-6926HIGH7.5The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate...
CVE-2015-9251jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi...
CVE-2015-7486Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim ...
CVE-2015-7485Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now