2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8831 | — | — | 2.1% | Feb 9, 2017 | Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to injec... |
| CVE-2015-6024 | — | — | 26.1% | Feb 9, 2017 | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot... |
| CVE-2015-6023 | — | — | 11.0% | Feb 9, 2017 | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot... |
| CVE-2015-7494 | — | — | 0.2% | Feb 8, 2017 | A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admi... |
| CVE-2015-7493 | — | — | 0.3% | Feb 8, 2017 | IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during instal... |
| CVE-2015-7418 | — | — | 0.4% | Feb 8, 2017 | IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory ins... |
| CVE-2015-1976 | — | — | 0.3% | Feb 8, 2017 | IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool tha... |
| CVE-2015-8544 | — | — | 2.0% | Feb 7, 2017 | NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive i... |
| CVE-2015-8322 | — | — | 2.5% | Feb 7, 2017 | NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspe... |
| CVE-2015-7599 | — | — | 5.9% | Feb 7, 2017 | Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote ... |
| CVE-2015-8608 | — | — | 4.6% | Feb 7, 2017 | The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of... |
| CVE-2015-5677 | — | — | 0.5% | Feb 7, 2017 | bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows l... |
| CVE-2015-2794 | — | — | 74.6% | Feb 6, 2017 | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S... |
| CVE-2015-0229 | — | — | — | Feb 4, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ... |
| CVE-2015-4049 | — | — | 0.9% | Feb 3, 2017 | Unisys Libra 43xx, 63xx, and 83xx, and FS600 class systems with MCP-FIRMWARE 40.0 before 40.0IC4 Build 270 might allow r... |
| CVE-2015-8977 | — | — | 2.2% | Jan 31, 2017 | MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attacker... |
| CVE-2015-8976 | — | — | 1.0% | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Mer... |
| CVE-2015-8975 | — | — | 1.7% | Jan 31, 2017 | Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x befo... |
| CVE-2015-8974 | — | — | 2.1% | Jan 31, 2017 | SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) befo... |
| CVE-2015-8973 | — | — | 1.6% | Jan 31, 2017 | xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows... |
| CVE-2015-8034 | — | — | 0.4% | Jan 30, 2017 | The state.sls function in Salt before 2015.8.3 uses weak permissions on the cache data, which allows local users to obta... |
| CVE-2015-7331 | — | — | 1.2% | Jan 30, 2017 | The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vecto... |
| CVE-2015-2181 | — | — | 2.9% | Jan 30, 2017 | Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers t... |
| CVE-2015-2180 | — | — | 4.7% | Jan 30, 2017 | The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands... |
| CVE-2015-8158 | — | — | 7.6% | Jan 30, 2017 | The getresponse function in ntpq in NTP versions before 4.2.8p9 and 4.3.x before 4.3.90 allows remote attackers to cause... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now