2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-2883Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to devi...
CVE-2015-2882Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoo...
CVE-2015-2881Gynoii has a password of guest for the backdoor guest account and a password of 12345 for the backdoor admin account.
CVE-2015-2880TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.
CVE-2015-4673Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arb...
CVE-2015-8965CRITICAL9.8Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that...
CVE-2015-9019In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, whi...
CVE-2015-4680FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
CVE-2015-1612OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow...
CVE-2015-1611OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow...
CVE-2015-8671Huawei LogCenter V100R001C10 could allow an authenticated attacker to tamper with requests using a tool and submit a req...
CVE-2015-8670Huawei LogCenter V100R001C10 could allow an authenticated attacker to add abnormal device information to the log collect...
CVE-2015-7847Huawei MBB (Mobile Broadband) product E3272s with software versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00 h...
CVE-2015-7844Huawei FusionAccess with software V100R005C10,V100R005C20 could allow attackers to craft and send a malformed HDP protoc...
CVE-2015-2246The MeWidget module on Huawei P7 smartphones with software P7-L10 V100R001C00B136 and earlier versions could lead to the...
CVE-2015-4624Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
CVE-2015-8234The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification pr...
CVE-2015-4556The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a ...
CVE-2015-8764Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.
CVE-2015-8763The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) ...
CVE-2015-8762The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer de...
CVE-2015-8010Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga bef...
CVE-2015-0864Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to o...
CVE-2015-0863GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in...
CVE-2015-8310Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbit...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now