2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5490 | — | — | 2.6% | Aug 18, 2015 | The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebu... |
| CVE-2015-5489 | — | — | 1.0% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in the Smart Trim module 7.x-1.x before 7.x-1.5 for Drupal allows remote authen... |
| CVE-2015-5488 | — | — | 1.4% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.... |
| CVE-2015-5487 | — | — | 1.2% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 ... |
| CVE-2015-5482 | — | — | 1.8% | Aug 18, 2015 | Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administra... |
| CVE-2015-5481 | — | — | 2.1% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPre... |
| CVE-2015-4670 | — | — | 1.9% | Aug 18, 2015 | Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolk... |
| CVE-2015-4426 | — | — | 2.1% | Aug 18, 2015 | SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via t... |
| CVE-2015-4425 | — | — | 3.8% | Aug 18, 2015 | Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permi... |
| CVE-2015-6516 | — | — | 2.0% | Aug 18, 2015 | SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitra... |
| CVE-2015-6515 | — | — | 1.4% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.2.x before 6.2.4, 6.1.x before 6.1.8, 6.0.... |
| CVE-2015-6514 | — | — | 1.4% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Enterprise 6.2.x before 6.2.4 and Splunk Light 6.2.x... |
| CVE-2015-6513 | — | — | 2.2% | Aug 18, 2015 | Multiple SQL injection vulnerabilities in the J2Store (com_j2store) extension before 3.1.7 for Joomla! allow remote atta... |
| CVE-2015-6512 | — | — | 2.5% | Aug 18, 2015 | SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows ... |
| CVE-2015-6511 | — | — | 2.1% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script ... |
| CVE-2015-6510 | — | — | 2.1% | Aug 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.2.3 allow remote attackers to inject arbitrary w... |
| CVE-2015-6509 | — | — | 2.1% | Aug 18, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.2.3 allow remote attackers to inject arbitrary w... |
| CVE-2015-6508 | — | — | 2.2% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script ... |
| CVE-2015-5681 | — | — | 4.8% | Aug 18, 2015 | Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote att... |
| CVE-2015-5599 | — | — | 3.2% | Aug 18, 2015 | Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote atta... |
| CVE-2015-5485 | — | — | 2.1% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eve... |
| CVE-2015-4029 | — | — | 20.4% | Aug 18, 2015 | Cross-site scripting (XSS) vulnerability in the WebGUI in pfSense before 2.2.3 allows remote attackers to inject arbitra... |
| CVE-2015-6254 | — | — | 1.8% | Aug 17, 2015 | The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destin... |
| CVE-2015-0277 | — | — | 2.0% | Aug 17, 2015 | The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an ... |
| CVE-2015-5531 | — | — | 91.8% | Aug 17, 2015 | Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now