2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2015-9391MEDIUM6.1The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.
CVE-2015-9390MEDIUM4.3The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are ...
CVE-2015-9389MEDIUM5.4The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.
CVE-2015-9388MEDIUM6.5The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.
CVE-2015-9387MEDIUM6.5The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.
CVE-2015-9386MEDIUM6.1The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.
CVE-2015-9385MEDIUM6.1The quotes-and-tips plugin before 1.20 for WordPress has XSS.
CVE-2015-9384MEDIUM6.1The relevant plugin before 1.0.8 for WordPress has XSS.
CVE-2015-9383MEDIUM6.5FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
CVE-2015-9354MEDIUM4.8The gigpress plugin before 2.3.11 for WordPress has XSS.
CVE-2015-9320MEDIUM6.1The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
CVE-2015-9302MEDIUM6.1The simple-fields plugin before 1.4.11 for WordPress has XSS.
CVE-2015-9297MEDIUM6.1The events-manager plugin before 5.6 for WordPress has XSS.
CVE-2015-9304MEDIUM6.1The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
CVE-2015-5297MEDIUM6.7An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. ...
CVE-2015-6960MEDIUM6.1edx-platform before 2015-09-17 allows XSS via a team name.
CVE-2015-9289MEDIUM5.5In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends...
CVE-2015-2230MEDIUM6.1Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.
CVE-2015-1326MEDIUM5.7python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method cou...
CVE-2015-1320MEDIUM5.5The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface...
CVE-2015-1316MEDIUM6.4Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
CVE-2015-9267MEDIUM5.5Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local user...
CVE-2015-9261MEDIUM5.5huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and ...
CVE-2015-9260MEDIUM5.4An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjec...
CVE-2015-1857MEDIUM5.3The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveragin...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now