2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-8971HIGH7.8Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window titl...
CVE-2015-8862mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by lever...
CVE-2015-8861MEDIUM6.1The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by...
CVE-2015-8860The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an ...
CVE-2015-8859MEDIUM5.3The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
CVE-2015-8858The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via craft...
CVE-2015-8857CRITICAL9.8The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean ...
CVE-2015-8856MEDIUM6.1Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to ...
CVE-2015-8855The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long v...
CVE-2015-8854HIGH7.5The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecif...
CVE-2015-8315HIGH7.5The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long versi...
CVE-2015-7743XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to ...
CVE-2015-4626B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the busine...
CVE-2015-8212CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execut...
CVE-2015-8684Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attack...
CVE-2015-8667Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attack...
CVE-2015-3188The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecifi...
CVE-2015-6501Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect user...
CVE-2015-8020Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions ...
CVE-2015-4594eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a...
CVE-2015-4593eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ...
CVE-2015-4592eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow...
CVE-2015-4591eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo...
CVE-2015-7848HIGH7.5An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a spec...
CVE-2015-2868An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS serv...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now