2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-5515The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changi...
CVE-2015-5514Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x before 7.x-2.8 for Drupal, when the migrate_ui su...
CVE-2015-5513Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x befo...
CVE-2015-5512The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Vi...
CVE-2015-5511The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registr...
CVE-2015-5510Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attac...
CVE-2015-5509The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not pr...
CVE-2015-5508Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Too...
CVE-2015-5507Cross-site scripting (XSS) vulnerability in the Inline Entity Form module 7.x-1.x before 7.x-1.6 for Drupal allows remot...
CVE-2015-5506The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing,...
CVE-2015-5505The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not p...
CVE-2015-5504SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute...
CVE-2015-5503Open redirect vulnerability in the Chamilo integration module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers ...
CVE-2015-5502The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attache...
CVE-2015-5501The Hostmaster (Aegir) module 6.x-2.x before 6.x-2.4 and 7.x-3.x before 7.x-3.0-beta2 for Drupal allows remote attackers...
CVE-2015-5500Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certai...
CVE-2015-5499The Navigate module for Drupal does not properly check permissions, which allows remote authenticated users to modify cu...
CVE-2015-5498The Shipwire API module 7.x-1.x before 7.x-1.03 for Drupal does not check the view permission for the shipments overview...
CVE-2015-5497Cross-site scripting (XSS) vulnerability in the Web Links module 6.x-2.x before 6.x-2.6 and 7.x-1.x before 7.x-1.0 for D...
CVE-2015-5496The pass2pdf module for Drupal does not restrict access to generated PDF files, which allows remote attackers to obtain ...
CVE-2015-5495Cross-site scripting (XSS) vulnerability in the Mobile sliding menu module 7.x-2.x before 7.x-2.1 for Drupal allows remo...
CVE-2015-5494Cross-site scripting (XSS) vulnerability in the Webform Matrix Component module 7.x-4.x before 7.x-4.13 for Drupal allow...
CVE-2015-5493The Entityform Block module 7.x-1.x before 7.x-1.3 for Drupal does not properly check permissions when a form is locked ...
CVE-2015-5492Cross-site scripting (XSS) vulnerability in the Video Consultation module for Drupal allows remote attackers to inject a...
CVE-2015-5491The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now