KEV 2015
44 CISA Known Exploited Vulnerabilities from 2015
Critical 16
October 2025
April 2022
Adobe Flash Player — Zero-Day RCE Exploited by Angler Exploit Kit Before Patch; Malvertising Wave; Out-of-Band Patch APSB15-03
CVSS 9.8Adobe Flash Player — Use-After-Free Zero-Day Exploited via Malvertising Before Patch; Hanjuan/Neutrino Exploit Kits; Out-of-Band APSB15-04
CVSS 9.8Adobe Flash Player — Heap Buffer Overflow Zero-Day Exploited by APT3 ('Operation Clandestine Wolf') and Exploit Kits; Emergency APSB15-11 (June 2015)
CVSS 9.8Adobe Flash Player — UAF in AS3 DisplayObject Class; Second Hacking Team Breach Zero-Day; Patched APSB15-18 (July 2015)
CVSS 9.8Adobe Flash Player — UAF in AS3 BitmapData Class; Third Hacking Team Breach Zero-Day; Patched APSB15-18 (July 2015)
CVSS 9.8March 2022
D-Link / TRENDnet Routers — Ping Diagnostic Command Injection Enables Pre-Auth RCE as Root; EOL Devices; Exploited by Mirai Botnets
CVSS 9.8Elasticsearch — Groovy Scripting Sandbox Escape via Java Reflection Enables Unauthenticated OS Command Execution; Fixed 1.3.8 / 1.4.3
CVSS 9.8Oracle Java SE — Java Sandbox Bypass Enables Pre-Auth RCE; Exploit Kit Target; Oracle CPU July 2015; Fixed Java 8u51
CVSS 9.8Adobe Flash Player — Memory Corruption Zero-Day Exploited Before Patch; Angler/Magnitude Exploit Kits; Emergency APSB15-06 (April 2015)
CVSS 9.8Adobe Flash Player — UAF in AS3 ByteArray Class Zero-Day Exposed by Hacking Team Breach; Immediately Weaponized by All Major Exploit Kits; Emergency APSB15-16 (July 2015)
CVSS 9.8Arcserve UDP — Unauthenticated Directory Traversal Enables Remote File Read and Service Disruption on Enterprise Backup Infrastructure
CVSS 9.1February 2022
Windows HTTP.sys (MS15-034) — Integer Overflow in Range Header Parsing Enables Kernel RCE on IIS Servers; Public PoC Caused BSoDs; CVSS 9.8
CVSS 9.8D-Link DIR-645 — HNAP Interface Command Injection via GetDeviceSettings Enables Pre-Auth RCE as Root; EOL Device; Mirai Botnet Exploitation
CVSS 9.8January 2022
November 2021
High 25
May 2023
February 2023
May 2022
Windows Win32k.sys — Kernel-Mode Driver Memory Corruption Enables Privilege Escalation; Patched MS15-061 (June 2015)
CVSS 8.8Internet Explorer — Memory Corruption via Crafted Web Page Enables RCE; July 2015 Patch Tuesday; Patched MS15-065
CVSS 8.8Mozilla Firefox / PDF.js — Same Origin Policy Bypass via PDF.js Zero-Day Actively Used to Steal Local Files; Emergency Firefox 39.0.3 (August 2015)
CVSS 8.8Adobe Flash Player — Integer Overflow Zero-Day Exploited During Holiday Period; Eighth and Final Flash Zero-Day of 2015; Emergency APSB15-32 (December 2015)
CVSS 8.8Windows TS WebProxy — TSWbPrxy Directory Traversal Enables Privilege Escalation in Terminal Services Web Access; Patched MS15-004
CVSS 7.8Adobe Flash Player — Memory Address Disclosure Bypasses ASLR; Used with CVE-2015-0311 in Angler Exploit Kit Drive-By Attacks; Patched APSB15-02
CVSS 7.8Windows / Office / .NET / Silverlight — TrueType Font Parsing RCE Affects Multiple Microsoft Components; Patched MS15-044
CVSS 7.8Microsoft Windows Kernel — Local Privilege Escalation to SYSTEM via Crafted Application; Patched MS15-135 (December 2015)
CVSS 7.8April 2022
March 2022
Microsoft Office — Uninitialized Memory Corruption in Document Handling Enables Remote Code Execution; Patched MS15-059
CVSS 8.8Internet Explorer — JScript Engine Memory Corruption Enables RCE via Crafted Web Page; Patched MS15-065 (July 2015)
CVSS 8.8Windows ATMFD / OpenType — Hacking Team Zero-Day: Malformed OpenType Font in Document or Web Page Enables Kernel-Level RCE; Emergency Patch MS15-078
CVSS 8.8Microsoft PowerPoint — Memory Corruption in Presentation File Handling Enables RCE via Crafted Document; Patched MS15-070 (July 2015)
CVSS 8.8Windows Win32k.sys — Kernel Memory Corruption Enables Privilege Escalation to SYSTEM; Ransomware Use Confirmed; Patched MS15-097 (September 2015)
CVSS 8.2Microsoft Office — Memory Corruption in Document Processing Enables RCE via Crafted Document; Patched MS15-081 (August 2015)
CVSS 7.8Windows Win32k.sys — Zero-Day Kernel LPE Exploited by APT Before Patch; Used with IE RCE for Full-Chain Browser Compromise; Patched MS15-051
CVSS 7.8Windows ATMFD.DLL — Adobe Type Manager Font Driver Out-of-Bounds Write Enables Local Privilege Escalation; Hacking Team Context; Patched MS15-077
CVSS 7.8Microsoft Office — EPS Image Parser RCE via Crafted PostScript in Document; Exploited by Chinese-Nexus APTs; Microsoft Disabled EPS in Office 2017
CVSS 7.8Adobe Flash Player — Zero-Day Exploited by APT29 (Cozy Bear) in Targeted Attacks Against U.S. Government; Ransomware Use Confirmed; Emergency APSB15-27 (October 2015)
CVSS 7.8Cisco Prime DCNM — Unauthenticated fmserver Servlet Directory Traversal Allows Arbitrary File Read on Data Center Management Server; Fixed 7.1(1)
CVSS 7.5TP-Link Archer Routers — Unauthenticated Directory Traversal via login/ PATH_INFO Reads Arbitrary Files Including Device Credentials
CVSS 7.5February 2022
November 2021
Medium 3
May 2022
Windows Mount Manager — Symbolic Link Processing on USB Drive Insert Enables Privilege Escalation to SYSTEM; Physical Access Required; Patched MS15-085
CVSS 6.6Internet Explorer — ASLR Bypass via Crafted Web Page Enables Memory Layout Disclosure; Exploit Chain Enabler; Patched MS15-009
CVSS 6.5