2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5206 | — | — | 2.4% | Sep 13, 2017 | Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unkn... |
| CVE-2015-5168 | — | — | 2.4% | Sep 13, 2017 | Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown imp... |
| CVE-2015-2750 | — | — | 1.4% | Sep 13, 2017 | Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote att... |
| CVE-2015-2749 | — | — | 1.5% | Sep 13, 2017 | Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to a... |
| CVE-2015-9228 | — | — | 3.7% | Sep 12, 2017 | In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via... |
| CVE-2015-9227 | — | — | 2.5% | Sep 11, 2017 | PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCa... |
| CVE-2015-9226 | — | — | 2.0% | Sep 11, 2017 | Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands... |
| CVE-2015-8354 | — | — | 2.1% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remo... |
| CVE-2015-8353 | — | — | 2.1% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in the Role Scoper plugin before 1.3.67 for WordPress allows remote attackers t... |
| CVE-2015-8351 | — | — | 37.0% | Sep 11, 2017 | PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ... |
| CVE-2015-8350 | — | — | 2.6% | Sep 11, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remot... |
| CVE-2015-8349 | — | — | 3.3% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary ... |
| CVE-2015-5054 | — | — | 1.3% | Sep 11, 2017 | Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to... |
| CVE-2015-4689 | — | — | 2.3% | Sep 11, 2017 | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via ... |
| CVE-2015-4688 | — | — | 2.0% | Sep 11, 2017 | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a s... |
| CVE-2015-4687 | — | — | 1.2% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers t... |
| CVE-2015-7879 | — | — | 0.9% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x before 7.x-1.3 for Drupal allows remote authentica... |
| CVE-2015-7877 | — | — | 1.3% | Sep 11, 2017 | Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers... |
| CVE-2015-4523 | — | — | 4.3% | Sep 11, 2017 | Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtu... |
| CVE-2015-7672 | — | — | 1.3% | Sep 7, 2017 | Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27). |
| CVE-2015-5060 | — | — | 0.7% | Sep 7, 2017 | Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev. |
| CVE-2015-5052 | — | — | 1.0% | Sep 7, 2017 | SQL injection vulnerability in Sefrengo before 1.6.5 beta2. |
| CVE-2015-4724 | — | — | 0.8% | Sep 7, 2017 | SQL injection vulnerability in Concrete5 5.7.3.1. |
| CVE-2015-4721 | — | — | 0.7% | Sep 7, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1. |
| CVE-2015-4697 | — | — | 1.2% | Sep 7, 2017 | Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now