2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-6358Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allow...
CVE-2015-8239The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of...
CVE-2015-7778Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-...
CVE-2015-7503Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attacker...
CVE-2015-7384Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
CVE-2015-6918salt before 2015.5.5 leaks git usernames and passwords to the log.
CVE-2015-6521Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.
CVE-2015-5675The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial...
CVE-2015-5639niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-t...
CVE-2015-2988Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to exec...
CVE-2015-2856Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices ...
CVE-2015-7842Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R...
CVE-2015-2673The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC...
CVE-2015-2148Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.2 allow remote attackers to...
CVE-2015-2147Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbi...
CVE-2015-2146Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbi...
CVE-2015-2145Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to...
CVE-2015-2144Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticate...
CVE-2015-2143Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attac...
CVE-2015-2142Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authe...
CVE-2015-1828MEDIUM5.9The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtai...
CVE-2015-1429HIGH7.5Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit all...
CVE-2015-0296The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r324...
CVE-2015-5246The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain ac...
CVE-2015-2297nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application cras...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now