KEV 2015

44 CISA Known Exploited Vulnerabilities from 2015

Critical 16

October 2025

April 2022

March 2022

February 2022

January 2022

November 2021

High 25

May 2023

February 2023

May 2022

April 2022

March 2022

CVE-2015-1770

Microsoft Office — Uninitialized Memory Corruption in Document Handling Enables Remote Code Execution; Patched MS15-059

CVSS 8.8
CVE-2015-2419

Internet Explorer — JScript Engine Memory Corruption Enables RCE via Crafted Web Page; Patched MS15-065 (July 2015)

CVSS 8.8
CVE-2015-2426

Windows ATMFD / OpenType — Hacking Team Zero-Day: Malformed OpenType Font in Document or Web Page Enables Kernel-Level RCE; Emergency Patch MS15-078

CVSS 8.8
CVE-2015-2424

Microsoft PowerPoint — Memory Corruption in Presentation File Handling Enables RCE via Crafted Document; Patched MS15-070 (July 2015)

CVSS 8.8
CVE-2015-2546

Windows Win32k.sys — Kernel Memory Corruption Enables Privilege Escalation to SYSTEM; Ransomware Use Confirmed; Patched MS15-097 (September 2015)

CVSS 8.2
CVE-2015-1642

Microsoft Office — Memory Corruption in Document Processing Enables RCE via Crafted Document; Patched MS15-081 (August 2015)

CVSS 7.8
CVE-2015-1701

Windows Win32k.sys — Zero-Day Kernel LPE Exploited by APT Before Patch; Used with IE RCE for Full-Chain Browser Compromise; Patched MS15-051

CVSS 7.8
CVE-2015-2387

Windows ATMFD.DLL — Adobe Type Manager Font Driver Out-of-Bounds Write Enables Local Privilege Escalation; Hacking Team Context; Patched MS15-077

CVSS 7.8
CVE-2015-2545

Microsoft Office — EPS Image Parser RCE via Crafted PostScript in Document; Exploited by Chinese-Nexus APTs; Microsoft Disabled EPS in Office 2017

CVSS 7.8
CVE-2015-7645

Adobe Flash Player — Zero-Day Exploited by APT29 (Cozy Bear) in Targeted Attacks Against U.S. Government; Ransomware Use Confirmed; Emergency APSB15-27 (October 2015)

CVSS 7.8
CVE-2015-0666

Cisco Prime DCNM — Unauthenticated fmserver Servlet Directory Traversal Allows Arbitrary File Read on Data Center Management Server; Fixed 7.1(1)

CVSS 7.5
CVE-2015-3035

TP-Link Archer Routers — Unauthenticated Directory Traversal via login/ PATH_INFO Reads Arbitrary Files Including Device Credentials

CVSS 7.5

February 2022

November 2021

Medium 3

May 2022

March 2022