2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7224 | — | — | 1.7% | Dec 21, 2017 | puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a databas... |
| CVE-2015-4100 | — | — | 0.7% | Dec 21, 2017 | Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by l... |
| CVE-2015-8470 | — | — | 1.6% | Dec 11, 2017 | The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an... |
| CVE-2015-6502 | — | — | 1.1% | Dec 11, 2017 | Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to ... |
| CVE-2015-7269 | — | — | 0.3% | Nov 27, 2017 | Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow... |
| CVE-2015-7268 | — | — | 0.3% | Nov 27, 2017 | Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Window... |
| CVE-2015-7267 | — | — | 0.3% | Nov 27, 2017 | Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode ... |
| CVE-2015-3934 | — | — | 3.1% | Nov 21, 2017 | Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands vi... |
| CVE-2015-7501 | — | — | 83.3% | Nov 9, 2017 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5... |
| CVE-2015-3933 | — | — | 3.8% | Nov 8, 2017 | Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote ... |
| CVE-2015-7878 | — | — | 0.6% | Nov 6, 2017 | Cross-site scripting (XSS) vulnerability in the Taxonomy Find module 6.x-2.x through 6.x-1.2 and 7.x-2.x through 7.x-1.0... |
| CVE-2015-7529 | HIGH | 7.8 | 0.4% | Nov 6, 2017 | sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a sy... |
| CVE-2015-9245 | — | — | 1.9% | Oct 31, 2017 | Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to s... |
| CVE-2015-7549 | — | — | 0.4% | Oct 30, 2017 | The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a d... |
| CVE-2015-3249 | — | — | 5.4% | Oct 30, 2017 | The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of... |
| CVE-2015-0226 | — | — | 5.5% | Oct 30, 2017 | Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting... |
| CVE-2015-0224 | — | — | 15.1% | Oct 30, 2017 | qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted ... |
| CVE-2015-1835 | — | — | 5.9% | Oct 27, 2017 | Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml... |
| CVE-2015-5173 | HIGH | 8.8 | 1.0% | Oct 24, 2017 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.... |
| CVE-2015-5172 | CRITICAL | 9.8 | 1.2% | Oct 24, 2017 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.... |
| CVE-2015-5171 | CRITICAL | 9.8 | 1.2% | Oct 24, 2017 | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Fo... |
| CVE-2015-5170 | HIGH | 8.8 | 0.8% | Oct 24, 2017 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.... |
| CVE-2015-6839 | — | — | 0.4% | Oct 23, 2017 | The parse function in MSA vot.Ar 3.1 does not check whether a candidate receives more than one vote, which allows physic... |
| CVE-2015-5533 | — | — | 7.2% | Oct 23, 2017 | SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote ... |
| CVE-2015-5532 | MEDIUM | 6.1 | 2.1% | Oct 23, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPr... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now