2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9254 | — | — | 1.1% | Feb 20, 2018 | Datto ALTO and SIRIS devices have a default VNC password. |
| CVE-2015-2081 | — | — | 2.9% | Feb 20, 2018 | Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts. |
| CVE-2015-9253 | — | — | 4.3% | Feb 19, 2018 | An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master proce... |
| CVE-2015-2324 | — | — | 0.9% | Feb 19, 2018 | Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allo... |
| CVE-2015-9252 | — | — | 1.1% | Feb 13, 2018 | An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral... |
| CVE-2015-1862 | — | — | 3.1% | Feb 9, 2018 | The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot... |
| CVE-2015-2329 | — | — | 1.2% | Feb 8, 2018 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to... |
| CVE-2015-4400 | — | — | 0.7% | Feb 6, 2018 | Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless networ... |
| CVE-2015-3619 | — | — | 0.8% | Feb 6, 2018 | Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! a... |
| CVE-2015-3618 | — | — | 1.4% | Feb 6, 2018 | Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attack... |
| CVE-2015-5674 | — | — | 2.6% | Feb 5, 2018 | The routed daemon in FreeBSD 9.3 before 9.3-RELEASE-p22, 10.2-RC2 before 10.2-RC2-p1, 10.2-RC1 before 10.2-RC1-p2, 10.2 ... |
| CVE-2015-4461 | — | — | 1.2% | Feb 5, 2018 | Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensiti... |
| CVE-2015-4412 | — | — | 4.8% | Feb 5, 2018 | BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attacker... |
| CVE-2015-4179 | — | — | 0.9% | Feb 5, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Codestyling Localization plugin 1.99.30 and earlier fo... |
| CVE-2015-1418 | — | — | 3.8% | Feb 5, 2018 | The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 b... |
| CVE-2015-1416 | — | — | 3.5% | Feb 5, 2018 | Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEAS... |
| CVE-2015-2186 | — | — | 1.1% | Feb 3, 2018 | The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use ... |
| CVE-2015-2796 | — | — | 1.1% | Feb 2, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject ar... |
| CVE-2015-2204 | — | — | 3.2% | Feb 1, 2018 | Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access ... |
| CVE-2015-2203 | — | — | 2.2% | Feb 1, 2018 | Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive sett... |
| CVE-2015-1142857 | — | — | 2.5% | Jan 23, 2018 | On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF... |
| CVE-2015-6926 | HIGH | 7.5 | 1.1% | Jan 19, 2018 | The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate... |
| CVE-2015-9251 | — | — | 30.2% | Jan 18, 2018 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi... |
| CVE-2015-7486 | — | — | 0.7% | Jan 16, 2018 | Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim ... |
| CVE-2015-7485 | — | — | 0.7% | Jan 16, 2018 | Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim ... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now