2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-4393 | — | — | 1.7% | Jun 15, 2015 | The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authen... |
| CVE-2015-4392 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-2.7 for Drupal allows remote authenticated user... |
| CVE-2015-4391 | — | — | 0.7% | Jun 15, 2015 | Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x ... |
| CVE-2015-4390 | — | — | 0.7% | Jun 15, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the User Import module 6.x-4.x before 6.x-4.4 and 7.x-2.x ... |
| CVE-2015-4389 | — | — | 1.1% | Jun 15, 2015 | The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content t... |
| CVE-2015-4388 | — | — | 1.2% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Current Search Links module 7.x-1.x before 7.x-1.1 for Drupal, when the ... |
| CVE-2015-4387 | — | — | 1.2% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x befor... |
| CVE-2015-4386 | — | — | 1.2% | Jun 15, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7... |
| CVE-2015-4385 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Imagefield Info module 7.x-1.x befor... |
| CVE-2015-4384 | — | — | 1.1% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Ubercart Webform Checkout Pane module 6.x-3.x before 6.x-3.10 and 7.x-3.... |
| CVE-2015-4383 | — | — | 0.6% | Jun 15, 2015 | Cross-site request forgery (CSRF) vulnerability in the Decisions module for Drupal allows remote attackers to hijack the... |
| CVE-2015-4382 | — | — | 0.7% | Jun 15, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x befo... |
| CVE-2015-4381 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Dru... |
| CVE-2015-4380 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Linear Case module 6.x-1.x before 6.x-1.3 for Drupal allows remote authe... |
| CVE-2015-4379 | — | — | 0.7% | Jun 15, 2015 | Cross-site request forgery (CSRF) vulnerability in the Webform Multiple File Upload module 6.x-1.x before 6.x-1.3 and 7.... |
| CVE-2015-4378 | — | — | 0.9% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Crumbs module 7.x-2.x before 7.x-2.3 for Drupal allows remote authentica... |
| CVE-2015-4377 | — | — | 0.9% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Petition module 6.x-1.x before 6.x-1... |
| CVE-2015-4376 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Profile2 Privacy module 7.x-1.x before 7.x-1.5 for Drupal allows remote ... |
| CVE-2015-4375 | — | — | 1.2% | Jun 15, 2015 | The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node ... |
| CVE-2015-4373 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated use... |
| CVE-2015-4372 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Image Title module before 7.x-1.1 for Drupal allows remote authenticated... |
| CVE-2015-4371 | — | — | 1.2% | Jun 15, 2015 | Open redirect vulnerability in the Perfecto module before 7.x-1.2 for Drupal allows remote attackers to redirect users t... |
| CVE-2015-4370 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Site Documentation module before 6.x-1.5 for Drupal allows remote authen... |
| CVE-2015-4369 | — | — | 1.0% | Jun 15, 2015 | Cross-site scripting (XSS) vulnerability in the Trick Question module before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drup... |
| CVE-2015-4368 | — | — | 1.4% | Jun 15, 2015 | The Commerce Ogone module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to complete the checkout for an orde... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now