2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-7317Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated...
CVE-2015-7316Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 ...
CVE-2015-7315Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0r...
CVE-2015-6748MEDIUM6.1Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
CVE-2015-5282Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
CVE-2015-5237HIGH8.8protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
CVE-2015-4669The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the sy...
CVE-2015-4668Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit...
CVE-2015-4667Multiple hardcoded credentials in Xsuite 2.x.
CVE-2015-3887Untrusted search path vulnerability in ProxyChains-NG before 4.9 allows local users to gain privileges via a Trojan hors...
CVE-2015-1187CRITICAL9.8The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr...
CVE-2015-8559HIGH7.5The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/...
CVE-2015-5284ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem,...
CVE-2015-4706Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web scrip...
CVE-2015-3296Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web ...
CVE-2015-0276Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2.
CVE-2015-9232The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Deleg...
CVE-2015-9231iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature wa...
CVE-2015-7347Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
CVE-2015-6673Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32.
CVE-2015-5608Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
CVE-2015-5395HIGH8.8Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
CVE-2015-4707MEDIUM6.1Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or...
CVE-2015-3890HIGH7.5Use-after-free vulnerability in Open Litespeed before 1.3.10.
CVE-2015-2927node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now