2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-8796 | — | — | 3.3% | Feb 15, 2016 | Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr befor... |
| CVE-2015-8795 | — | — | 2.7% | Feb 15, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to ... |
| CVE-2015-8531 | — | — | 0.8% | Feb 15, 2016 | Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.... |
| CVE-2015-7492 | — | — | 0.6% | Feb 15, 2016 | Cross-site scripting (XSS) vulnerability in Reference Data Management (RDM) in IBM InfoSphere Master Data Management 10.... |
| CVE-2015-7472 | — | — | 1.6% | Feb 15, 2016 | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.... |
| CVE-2015-7444 | — | — | 0.9% | Feb 15, 2016 | The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search ind... |
| CVE-2015-7408 | — | — | 0.9% | Feb 15, 2016 | The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not... |
| CVE-2015-7398 | — | — | 0.6% | Feb 15, 2016 | Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and... |
| CVE-2015-5050 | — | — | 0.5% | Feb 15, 2016 | Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.... |
| CVE-2015-5042 | — | — | 1.8% | Feb 15, 2016 | IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x be... |
| CVE-2015-5012 | — | — | 1.6% | Feb 15, 2016 | The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, ... |
| CVE-2015-5010 | — | — | 1.6% | Feb 15, 2016 | IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not h... |
| CVE-2015-4991 | — | — | 0.3% | Feb 15, 2016 | IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 thro... |
| CVE-2015-4957 | — | — | 0.6% | Feb 15, 2016 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows ... |
| CVE-2015-4956 | — | — | 0.9% | Feb 15, 2016 | The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspec... |
| CVE-2015-3197 | — | — | 10.7% | Feb 15, 2016 | ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which mak... |
| CVE-2015-2008 | — | — | 0.8% | Feb 15, 2016 | IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup op... |
| CVE-2015-2005 | — | — | 1.1% | Feb 15, 2016 | IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions,... |
| CVE-2015-8630 | — | — | 4.3% | Feb 13, 2016 | The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in... |
| CVE-2015-7681 | — | — | — | Feb 10, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Notes: none |
| CVE-2015-7680 | — | — | 2.1% | Feb 10, 2016 | Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the us... |
| CVE-2015-7679 | — | — | 1.4% | Feb 10, 2016 | Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitr... |
| CVE-2015-7678 | — | — | 0.9% | Feb 10, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote ... |
| CVE-2015-7677 | — | — | 3.0% | Feb 10, 2016 | The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileI... |
| CVE-2015-7675 | — | — | 3.1% | Feb 10, 2016 | The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authentic... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now