2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5695 | — | — | 2.1% | Aug 31, 2017 | Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records p... |
| CVE-2015-8334 | — | — | 0.9% | Aug 29, 2017 | SQL injection vulnerability in the Operation and Maintenance Unit (OMU) in Huawei VCN500 before V100R002C00SPC201 allows... |
| CVE-2015-8299 | — | — | 6.2% | Aug 29, 2017 | Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute ... |
| CVE-2015-7517 | — | — | 4.2% | Aug 29, 2017 | Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote ... |
| CVE-2015-7255 | — | — | 2.0% | Aug 29, 2017 | ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certifica... |
| CVE-2015-6942 | — | — | 0.9% | Aug 29, 2017 | Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2015-6588 | — | — | 1.2% | Aug 29, 2017 | Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to in... |
| CVE-2015-5209 | — | — | 9.1% | Aug 29, 2017 | Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect... |
| CVE-2015-4649 | — | — | 1.7% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t... |
| CVE-2015-3657 | — | — | 1.1% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level admi... |
| CVE-2015-3656 | — | — | 1.1% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level admi... |
| CVE-2015-3655 | HIGH | 8.8 | 0.7% | Aug 29, 2017 | Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before... |
| CVE-2015-3654 | — | — | 1.7% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t... |
| CVE-2015-3653 | — | — | 2.3% | Aug 29, 2017 | Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t... |
| CVE-2015-0234 | — | — | 1.3% | Aug 29, 2017 | Multiple temporary file creation vulnerabilities in pki-core 10.2.0. |
| CVE-2015-8332 | — | — | 1.0% | Aug 28, 2017 | Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities an... |
| CVE-2015-8300 | — | — | 0.6% | Aug 28, 2017 | Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\poly... |
| CVE-2015-1600 | — | — | 2.8% | Aug 28, 2017 | Information disclosure vulnerability in Netatmo Indoor Module firmware 100 and earlier. |
| CVE-2015-1554 | — | — | 1.5% | Aug 28, 2017 | kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash). |
| CVE-2015-0233 | — | — | 0.4% | Aug 28, 2017 | Multiple insecure Temporary File vulnerabilities in 389 Administration Server before 1.1.38. |
| CVE-2015-3976 | — | — | 1.2% | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multili... |
| CVE-2015-2046 | — | — | 1.9% | Aug 28, 2017 | Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20. |
| CVE-2015-1876 | — | — | 3.1% | Aug 28, 2017 | Directory traversal vulnerability in ES File Explorer 3.2.4.1. |
| CVE-2015-1445 | — | — | 1.8% | Aug 28, 2017 | HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30. |
| CVE-2015-1443 | — | — | 3.5% | Aug 28, 2017 | The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now