2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-10148 | HIGH | 8.8 | 0.3% | Apr 3, 2026 | Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical... |
| CVE-2015-20117 | HIGH | 8.8 | 0.2% | Mar 16, 2026 | Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated a... |
| CVE-2015-10145 | HIGH | 8.8 | 0.6% | Dec 31, 2025 | Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utilit... |
| CVE-2015-10144 | HIGH | 8.8 | 2.1% | Jul 25, 2025 | The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sa... |
| CVE-2015-10140 | HIGH | 8.8 | 1.0% | Jul 22, 2025 | The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authentic... |
| CVE-2015-10139 | HIGH | 8.8 | 1.0% | Jul 19, 2025 | The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import... |
| CVE-2015-10136 | HIGH | 7.5 | 2.0% | Jul 19, 2025 | The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' p... |
| CVE-2015-10134 | HIGH | 7.5 | 1.2% | Jul 19, 2025 | The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10... |
| CVE-2015-10133 | HIGH | 7.2 | 1.4% | Jul 19, 2025 | The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 vi... |
| CVE-2015-2079 | HIGH | 8.8 | 1.0% | Apr 28, 2025 | Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the t... |
| CVE-2015-10123 | HIGH | 8.8 | 0.6% | Mar 13, 2024 | An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user... |
| CVE-2015-8314 | HIGH | 7.5 | 0.6% | Dec 12, 2023 | The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain... |
| CVE-2015-20110 | HIGH | 7.5 | 0.6% | Oct 31, 2023 | JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that s... |
| CVE-2015-10125 | HIGH | 8.8 | 0.4% | Oct 5, 2023 | A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This aff... |
| CVE-2015-8371 | HIGH | 8.8 | 0.7% | Sep 21, 2023 | Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-c... |
| CVE-2015-2202 | HIGH | 7.2 | 0.7% | Sep 5, 2023 | Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the und... |
| CVE-2015-2201 | HIGH | 7.2 | 1.1% | Sep 5, 2023 | Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by ad... |
| CVE-2015-1391 | HIGH | 8.8 | 0.3% | Sep 5, 2023 | Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism. |
| CVE-2015-10116 | HIGH | 8.8 | 0.5% | Jun 6, 2023 | A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPres... |
| CVE-2015-10109 | HIGH | 8.8 | 0.4% | Jun 1, 2023 | A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. It has been rated as problemati... |
| CVE-2015-10108 | HIGH | 8.8 | 0.4% | May 31, 2023 | A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as p... |
| CVE-2015-10106 | HIGH | 8.8 | 0.6% | May 28, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in mback2k mh_httpbl Extension up to 1.... |
| CVE-2015-10096 | HIGH | 8.1 | 1.8% | Mar 20, 2023 | A vulnerability, which was classified as critical, was found in Zarthus IRC Twitter Announcer Bot up to 1.1.0. This affe... |
| CVE-2015-10087 | HIGH | 8.8 | 1.1% | Mar 7, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and c... |
| CVE-2015-10091 | HIGH | 7.2 | 0.6% | Mar 6, 2023 | A vulnerability has been found in ByWater Solutions bywater-koha-xslt and classified as critical. This vulnerability aff... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now