2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7484 | — | — | 1.0% | Jan 16, 2018 | IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remo... |
| CVE-2015-7474 | — | — | 0.7% | Jan 16, 2018 | Cross-site scripting (XSS) vulnerability in Jazz Foundation in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0... |
| CVE-2015-9250 | — | — | 1.7% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmen... |
| CVE-2015-9249 | — | — | 1.1% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/Versi... |
| CVE-2015-9248 | — | — | 0.5% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the titl... |
| CVE-2015-9247 | — | — | 0.5% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyb... |
| CVE-2015-9246 | — | — | 2.9% | Jan 12, 2018 | An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archiv... |
| CVE-2015-3888 | — | — | 1.1% | Jan 12, 2018 | Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers ... |
| CVE-2015-2981 | — | — | 0.8% | Jan 12, 2018 | The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-... |
| CVE-2015-2298 | — | — | 2.3% | Jan 12, 2018 | node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information... |
| CVE-2015-1290 | — | — | 3.3% | Jan 9, 2018 | The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote... |
| CVE-2015-1208 | — | — | 1.5% | Jan 9, 2018 | Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers t... |
| CVE-2015-2320 | — | — | 3.5% | Jan 8, 2018 | The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-sid... |
| CVE-2015-2319 | — | — | 3.2% | Jan 8, 2018 | The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_R... |
| CVE-2015-2318 | — | — | 2.0% | Jan 8, 2018 | The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequen... |
| CVE-2015-8008 | — | — | 2.8% | Dec 29, 2017 | The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allow... |
| CVE-2015-3302 | — | — | 21.7% | Dec 29, 2017 | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1... |
| CVE-2015-7889 | — | — | 2.2% | Dec 28, 2017 | The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f... |
| CVE-2015-3637 | — | — | 1.4% | Dec 28, 2017 | SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute ... |
| CVE-2015-7669 | — | — | 7.1% | Dec 27, 2017 | Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the ... |
| CVE-2015-7668 | — | — | 2.1% | Dec 27, 2017 | Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPre... |
| CVE-2015-7667 | — | — | 1.5% | Dec 27, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/ads... |
| CVE-2015-7666 | — | — | 1.8% | Dec 27, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functio... |
| CVE-2015-7324 | — | — | 1.8% | Dec 27, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) compo... |
| CVE-2015-6237 | — | — | 1.7% | Dec 27, 2017 | The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass au... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now