2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-5379Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 a...
CVE-2015-2878Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijac...
CVE-2015-5699The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute a...
CVE-2015-5177Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers...
CVE-2015-6668The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the ...
CVE-2015-4422The TEEOS module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users with root pe...
CVE-2015-4421The tzdriver module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users to gain p...
CVE-2015-6961Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary we...
CVE-2015-5740The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remot...
CVE-2015-5739The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allow...
CVE-2015-5376SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to...
CVE-2015-5227The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parame...
CVE-2015-7943Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x...
CVE-2015-7715HIGH8.8Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows ...
CVE-2015-7714HIGH7.2Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm...
CVE-2015-1239MEDIUM6.5Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, ...
CVE-2015-5164The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users...
CVE-2015-3400sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to t...
CVE-2015-2156Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play F...
CVE-2015-7806Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7....
CVE-2015-7504HIGH8.8Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cau...
CVE-2015-7687Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or e...
CVE-2015-4650Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access...
CVE-2015-3229fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use...
CVE-2015-2780Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a cra...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now