2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-20112LOW3.4RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption on a private network.
CVE-2015-0849LOW3.9pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability.
CVE-2015-0843CRITICAL9.8yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.
CVE-2015-0842CRITICAL9.8yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.
CVE-2015-4582MEDIUM6.1The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: C...
CVE-2015-2079HIGH8.8Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the t...
CVE-2015-20111CRITICAL9.8miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values...
CVE-2015-10132LOW3.5A vulnerability classified as problematic was found in Thimo Grauerholz WP-Spreadplugin up to 3.8.6.1 on WordPress. This...
CVE-2015-10131LOW3.5A vulnerability was found in chrisy TFO Graphviz Plugin up to 1.9 on WordPress and classified as problematic. Affected b...
CVE-2015-10123HIGH8.8An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user...
CVE-2015-10130MEDIUM4.3The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1...
CVE-2015-10129MEDIUM5.9A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some un...
CVE-2015-10128MEDIUM6.1A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by thi...
CVE-2015-10127MEDIUM6.1A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this...
CVE-2015-8314HIGH7.5The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain...
CVE-2015-2179MEDIUM5.5The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and ...
CVE-2015-2968MEDIUM5.9LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since ...
CVE-2015-0897MEDIUM5.9LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the...
CVE-2015-20110HIGH7.5JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that s...
CVE-2015-10126CRITICAL9.8A vulnerability classified as critical was found in Easy2Map Photos Plugin 1.0.1 on WordPress. This vulnerability affect...
CVE-2015-10125HIGH8.8A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This aff...
CVE-2015-10124CRITICAL9.8A vulnerability was found in Most Popular Posts Widget Plugin up to 0.8 on WordPress. It has been classified as critical...
CVE-2015-6964MEDIUM5.3MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into...
CVE-2015-8371HIGH8.8Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-c...
CVE-2015-5467CRITICAL9.8web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now