2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5379 | — | — | 1.6% | Oct 23, 2017 | Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 a... |
| CVE-2015-2878 | — | — | 4.2% | Oct 23, 2017 | Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijac... |
| CVE-2015-5699 | — | — | 0.4% | Oct 22, 2017 | The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute a... |
| CVE-2015-5177 | — | — | 6.3% | Oct 22, 2017 | Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers... |
| CVE-2015-6668 | — | — | 10.0% | Oct 19, 2017 | The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the ... |
| CVE-2015-4422 | — | — | 0.6% | Oct 19, 2017 | The TEEOS module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users with root pe... |
| CVE-2015-4421 | — | — | 0.9% | Oct 19, 2017 | The tzdriver module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users to gain p... |
| CVE-2015-6961 | — | — | 1.0% | Oct 18, 2017 | Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary we... |
| CVE-2015-5740 | — | — | 3.7% | Oct 18, 2017 | The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remot... |
| CVE-2015-5739 | — | — | 9.4% | Oct 18, 2017 | The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allow... |
| CVE-2015-5376 | — | — | 1.2% | Oct 18, 2017 | SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to... |
| CVE-2015-5227 | — | — | 2.9% | Oct 18, 2017 | The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parame... |
| CVE-2015-7943 | — | — | 1.8% | Oct 18, 2017 | Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x... |
| CVE-2015-7715 | HIGH | 8.8 | 3.1% | Oct 18, 2017 | Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows ... |
| CVE-2015-7714 | HIGH | 7.2 | 2.2% | Oct 18, 2017 | Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm... |
| CVE-2015-1239 | MEDIUM | 6.5 | 1.0% | Oct 18, 2017 | Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, ... |
| CVE-2015-5164 | — | — | 4.0% | Oct 18, 2017 | The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users... |
| CVE-2015-3400 | — | — | 1.6% | Oct 18, 2017 | sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to t... |
| CVE-2015-2156 | — | — | 5.4% | Oct 18, 2017 | Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play F... |
| CVE-2015-7806 | — | — | 6.0% | Oct 17, 2017 | Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.... |
| CVE-2015-7504 | HIGH | 8.8 | 0.6% | Oct 16, 2017 | Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cau... |
| CVE-2015-7687 | — | — | 4.1% | Oct 16, 2017 | Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or e... |
| CVE-2015-4650 | — | — | 6.0% | Oct 16, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access... |
| CVE-2015-3229 | — | — | 2.0% | Oct 16, 2017 | fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use... |
| CVE-2015-2780 | — | — | 15.1% | Oct 16, 2017 | Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a cra... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now