2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8349 | — | — | 3.3% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary ... |
| CVE-2015-5054 | — | — | 1.3% | Sep 11, 2017 | Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to... |
| CVE-2015-4689 | — | — | 2.3% | Sep 11, 2017 | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via ... |
| CVE-2015-4688 | — | — | 2.0% | Sep 11, 2017 | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a s... |
| CVE-2015-4687 | — | — | 1.2% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers t... |
| CVE-2015-7879 | — | — | 0.9% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x before 7.x-1.3 for Drupal allows remote authentica... |
| CVE-2015-7877 | — | — | 1.3% | Sep 11, 2017 | Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers... |
| CVE-2015-4523 | — | — | 4.3% | Sep 11, 2017 | Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtu... |
| CVE-2015-8079 | MEDIUM | 5.3 | 1.2% | Sep 7, 2017 | qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db. |
| CVE-2015-7672 | — | — | 1.3% | Sep 7, 2017 | Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27). |
| CVE-2015-5060 | — | — | 0.7% | Sep 7, 2017 | Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev. |
| CVE-2015-5052 | — | — | 1.0% | Sep 7, 2017 | SQL injection vulnerability in Sefrengo before 1.6.5 beta2. |
| CVE-2015-4724 | — | — | 0.8% | Sep 7, 2017 | SQL injection vulnerability in Concrete5 5.7.3.1. |
| CVE-2015-4721 | — | — | 0.7% | Sep 7, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1. |
| CVE-2015-4697 | — | — | 1.2% | Sep 7, 2017 | Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563. |
| CVE-2015-4629 | — | — | 1.7% | Sep 7, 2017 | Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN... |
| CVE-2015-4627 | — | — | 1.0% | Sep 7, 2017 | SQL injection vulnerability in Pragyan CMS 3.0. |
| CVE-2015-4619 | — | — | 0.9% | Sep 7, 2017 | Cross-site request forgery (CSRF) vulnerability in Spina before commit bfe44f289e336f80b6593032679300c493735e75. |
| CVE-2015-4085 | — | — | 2.3% | Sep 7, 2017 | Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1. |
| CVE-2015-3991 | — | — | 4.6% | Sep 7, 2017 | strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code... |
| CVE-2015-3314 | — | — | 4.9% | Sep 7, 2017 | SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. |
| CVE-2015-3313 | — | — | 8.3% | Sep 7, 2017 | SQL injection vulnerability in WordPress Community Events plugin before 1.4. |
| CVE-2015-3222 | — | — | 2.0% | Sep 7, 2017 | syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root. |
| CVE-2015-3169 | — | — | 1.1% | Sep 7, 2017 | Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch. |
| CVE-2015-1590 | — | — | 0.4% | Sep 7, 2017 | The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now