2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-20067HIGH7.5The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated us...
CVE-2015-20019MEDIUM5.4The Content text slider on post WordPress plugin before 6.9 does not sanitise and escape the Title and Message/Content s...
CVE-2015-10001MEDIUM4.3The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of ...
CVE-2015-7731MEDIUM5.5SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the ...
CVE-2015-2074HIGH7.5The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arb...
CVE-2015-2073HIGH7.5The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitra...
CVE-2015-2100HIGH8.8Multiple stack-based buffer overflows in WebGate eDVR Manager and Control Center allow remote attackers to execute arbit...
CVE-2015-2099HIGH8.8Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vec...
CVE-2015-2098HIGH8.8Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe...
CVE-2015-1877HIGH8.8The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly hand...
CVE-2015-20001HIGH7.5In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent s...
CVE-2015-9551CRITICAL9.8An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. ...
CVE-2015-9550HIGH7.5An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. ...
CVE-2015-1826Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2015-1825Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2015-1824Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2015-1823Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2015-0300Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2015-7380Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2015-7379Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2015-4719CRITICAL9.8The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a cra...
CVE-2015-8033MEDIUM5.3In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
CVE-2015-8032MEDIUM5.3In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
CVE-2015-9549MEDIUM6.1A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME ...
CVE-2015-5238Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-3796. Reason: This candidate is a reservation du...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now