2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-10148HIGH8.8Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical...
CVE-2015-20121CRITICAL9.8Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to ma...
CVE-2015-20120CRITICAL9.8Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unaut...
CVE-2015-20119MEDIUM5.4Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated at...
CVE-2015-20118MEDIUM6.1Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name paramet...
CVE-2015-20117HIGH8.8Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated a...
CVE-2015-20116MEDIUM6.1Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicio...
CVE-2015-20115MEDIUM6.1Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious sc...
CVE-2015-20114MEDIUM6.1Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute ar...
CVE-2015-20113MEDIUM4.3Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabi...
CVE-2015-10145HIGH8.8Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utilit...
CVE-2015-10147MEDIUM4.9The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all v...
CVE-2015-10146MEDIUM4.9The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ver...
CVE-2015-10142MEDIUM6.9Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior t...
CVE-2015-10144HIGH8.8The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sa...
CVE-2015-10143CRITICAL9.8The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio...
CVE-2015-10141CRITICAL9.3An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging e...
CVE-2015-10140HIGH8.8The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authentic...
CVE-2015-10137CRITICAL9.8The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi...
CVE-2015-10139HIGH8.8The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import...
CVE-2015-10138CRITICAL9.8The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2015-10136HIGH7.5The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' p...
CVE-2015-10135CRITICAL9.8The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2015-10134HIGH7.5The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10...
CVE-2015-10133HIGH7.2The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 vi...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now