2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5745 | MEDIUM | 6.5 | 3.0% | Jan 23, 2020 | Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users ... |
| CVE-2015-5278 | MEDIUM | 6.5 | 2.3% | Jan 23, 2020 | The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (inf... |
| CVE-2015-5239 | MEDIUM | 6.5 | 3.6% | Jan 23, 2020 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process c... |
| CVE-2015-6591 | MEDIUM | 5.5 | 0.6% | Jan 15, 2020 | Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and ea... |
| CVE-2015-5072 | MEDIUM | 6.5 | 1.7% | Jan 15, 2020 | The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote... |
| CVE-2015-5071 | MEDIUM | 6.5 | 1.8% | Jan 15, 2020 | AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote auth... |
| CVE-2015-5484 | MEDIUM | 5.4 | 1.4% | Jan 15, 2020 | Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated use... |
| CVE-2015-3147 | MEDIUM | 6.5 | 1.1% | Jan 14, 2020 | daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-up... |
| CVE-2015-2326 | MEDIUM | 5.5 | 1.6% | Jan 14, 2020 | The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a ... |
| CVE-2015-0558 | MEDIUM | 5.3 | 1.2% | Jan 14, 2020 | The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6, and possibly other ro... |
| CVE-2015-4039 | MEDIUM | 5.4 | 2.8% | Jan 6, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent... |
| CVE-2015-9540 | MEDIUM | 6.1 | 0.7% | Jan 4, 2020 | Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503. |
| CVE-2015-5595 | MEDIUM | 6.5 | 1.5% | Dec 31, 2019 | Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack ... |
| CVE-2015-5593 | MEDIUM | 6.1 | 1.1% | Dec 31, 2019 | The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attacker... |
| CVE-2015-5592 | MEDIUM | 6.1 | 1.3% | Dec 31, 2019 | Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting... |
| CVE-2015-8313 | MEDIUM | 5.9 | 1.7% | Dec 20, 2019 | GnuTLS incorrectly validates the first byte of padding in CBC modes |
| CVE-2015-3425 | MEDIUM | 6.1 | 0.9% | Dec 9, 2019 | Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows... |
| CVE-2015-1853 | MEDIUM | 6.5 | 1.7% | Dec 9, 2019 | chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows... |
| CVE-2015-7542 | MEDIUM | 5.3 | 0.4% | Dec 3, 2019 | A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates. |
| CVE-2015-0837 | MEDIUM | 5.9 | 2.0% | Nov 29, 2019 | The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information... |
| CVE-2015-2060 | MEDIUM | 5.3 | 2.3% | Nov 29, 2019 | cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers t... |
| CVE-2015-1855 | MEDIUM | 5.9 | 2.8% | Nov 29, 2019 | verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x ... |
| CVE-2015-9539 | MEDIUM | 6.1 | 1.6% | Nov 26, 2019 | The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS. |
| CVE-2015-9538 | MEDIUM | 6.5 | 10.1% | Nov 26, 2019 | The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection. |
| CVE-2015-9537 | MEDIUM | 5.4 | 1.2% | Nov 26, 2019 | The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_heig... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now