2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9391 | MEDIUM | 6.1 | 1.3% | Sep 20, 2019 | The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter. |
| CVE-2015-9390 | MEDIUM | 4.3 | 0.9% | Sep 20, 2019 | The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are ... |
| CVE-2015-9389 | MEDIUM | 5.4 | 0.8% | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name. |
| CVE-2015-9388 | MEDIUM | 6.5 | 0.7% | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. |
| CVE-2015-9387 | MEDIUM | 6.5 | 0.7% | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. |
| CVE-2015-9386 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation. |
| CVE-2015-9385 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | The quotes-and-tips plugin before 1.20 for WordPress has XSS. |
| CVE-2015-9384 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | The relevant plugin before 1.0.8 for WordPress has XSS. |
| CVE-2015-9383 | MEDIUM | 6.5 | 2.3% | Sep 3, 2019 | FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c. |
| CVE-2015-9354 | MEDIUM | 4.8 | 0.7% | Aug 28, 2019 | The gigpress plugin before 2.3.11 for WordPress has XSS. |
| CVE-2015-9320 | MEDIUM | 6.1 | 0.9% | Aug 20, 2019 | The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg. |
| CVE-2015-9302 | MEDIUM | 6.1 | 1.0% | Aug 13, 2019 | The simple-fields plugin before 1.4.11 for WordPress has XSS. |
| CVE-2015-9297 | MEDIUM | 6.1 | 0.9% | Aug 13, 2019 | The events-manager plugin before 5.6 for WordPress has XSS. |
| CVE-2015-9304 | MEDIUM | 6.1 | 1.0% | Aug 12, 2019 | The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input. |
| CVE-2015-5297 | MEDIUM | 6.7 | 1.5% | Jul 31, 2019 | An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. ... |
| CVE-2015-6960 | MEDIUM | 6.1 | 0.6% | Jul 29, 2019 | edx-platform before 2015-09-17 allows XSS via a team name. |
| CVE-2015-9289 | MEDIUM | 5.5 | 0.4% | Jul 27, 2019 | In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends... |
| CVE-2015-2230 | MEDIUM | 6.1 | 0.8% | May 30, 2019 | Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console. |
| CVE-2015-1326 | MEDIUM | 5.7 | 1.8% | Apr 22, 2019 | python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method cou... |
| CVE-2015-1320 | MEDIUM | 5.5 | 0.9% | Apr 22, 2019 | The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface... |
| CVE-2015-1316 | MEDIUM | 6.4 | 1.2% | Apr 22, 2019 | Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key. |
| CVE-2015-9267 | MEDIUM | 5.5 | 0.4% | Oct 1, 2018 | Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local user... |
| CVE-2015-9261 | MEDIUM | 5.5 | 2.4% | Jul 26, 2018 | huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and ... |
| CVE-2015-9260 | MEDIUM | 5.4 | 1.0% | Jul 5, 2018 | An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjec... |
| CVE-2015-1857 | MEDIUM | 5.3 | 1.7% | Apr 27, 2018 | The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveragin... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now