2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-2826 | — | — | 12.8% | Sep 20, 2017 | WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information. |
| CVE-2015-1866 | — | — | 1.1% | Sep 20, 2017 | Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2. |
| CVE-2015-1865 | MEDIUM | 5.1 | 0.2% | Sep 20, 2017 | fts.c in coreutils 8.4 allows local users to delete arbitrary files. |
| CVE-2015-0162 | — | — | 0.3% | Sep 20, 2017 | IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges. |
| CVE-2015-8224 | — | — | 0.6% | Sep 20, 2017 | Huawei P8 before GRA-CL00C92B210, before GRA-L09C432B200, before GRA-TL00C01B210, and before GRA-UL00C00B210 allows remo... |
| CVE-2015-5607 | — | — | 1.2% | Sep 20, 2017 | Cross-site request forgery in the REST API in IPython 2 and 3. |
| CVE-2015-5248 | — | — | 0.9% | Sep 20, 2017 | Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform. |
| CVE-2015-5179 | — | — | 1.1% | Sep 20, 2017 | FreeIPA might display user data improperly via vectors involving non-printable characters. |
| CVE-2015-4075 | HIGH | 8.1 | 7.4% | Sep 20, 2017 | The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted ... |
| CVE-2015-4074 | — | — | 56.5% | Sep 20, 2017 | Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read ar... |
| CVE-2015-4073 | — | — | 4.2% | Sep 20, 2017 | Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to exe... |
| CVE-2015-4072 | — | — | 2.9% | Sep 20, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote att... |
| CVE-2015-1329 | — | — | 4.6% | Sep 20, 2017 | Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow ... |
| CVE-2015-4685 | — | — | 1.2% | Sep 19, 2017 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain p... |
| CVE-2015-4684 | — | — | 4.9% | Sep 19, 2017 | Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) re... |
| CVE-2015-4683 | — | — | 6.9% | Sep 19, 2017 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potenti... |
| CVE-2015-4682 | — | — | 5.2% | Sep 19, 2017 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation... |
| CVE-2015-4681 | — | — | 1.7% | Sep 19, 2017 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors re... |
| CVE-2015-1849 | — | — | 1.7% | Sep 19, 2017 | AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain s... |
| CVE-2015-7837 | — | — | 0.4% | Sep 19, 2017 | The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secur... |
| CVE-2015-4089 | — | — | 1.0% | Sep 19, 2017 | Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest... |
| CVE-2015-3880 | — | — | 2.0% | Sep 19, 2017 | Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of G... |
| CVE-2015-3432 | — | — | 0.9% | Sep 19, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Pydio (formerly AjaXplorer) before 6.0.7 allow remote attackers t... |
| CVE-2015-3431 | — | — | 4.1% | Sep 19, 2017 | Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, ... |
| CVE-2015-3420 | — | — | 2.8% | Sep 19, 2017 | The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a den... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now