2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-4367Cross-site scripting (XSS) vulnerability in the Simple Subscription module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for...
CVE-2015-4366Cross-site scripting (XSS) vulnerability in the Mover module 6.x-1.0 for Drupal allows remote authenticated users with c...
CVE-2015-4365Cross-site scripting (XSS) vulnerability in the Taxonomy Accordion module for Drupal allows remote authenticated users w...
CVE-2015-4364Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign M...
CVE-2015-4363Open redirect vulnerability in the finder_form_goto function in the Finder module for Drupal allows remote attackers to ...
CVE-2015-4362Cross-site request forgery (CSRF) vulnerability in tracking_code.admin.inc in the Tracking Code module 7.x-1.x before 7....
CVE-2015-4361Cross-site request forgery (CSRF) vulnerability in the Registration codes module before 6.x-1.6 for Drupal allows remote...
CVE-2015-4360Cross-site request forgery (CSRF) vulnerability in the Registration codes module before 6.x-1.6, 6.x-2.x before 6.x-2.8,...
CVE-2015-4359Multiple cross-site scripting (XSS) vulnerabilities in the Registration codes module before 6.x-1.6, 6.x-2.x before 6.x-...
CVE-2015-4358Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Ubercart Discount Coupons module 6.x...
CVE-2015-4357Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x bef...
CVE-2015-4356Cross-site scripting (XSS) vulnerability in the view-based webform results table in the Webform module 7.x-4.x before 7....
CVE-2015-4355Cross-site request forgery (CSRF) vulnerability in the Watchdog Aggregator module for Drupal allows remote attackers to ...
CVE-2015-4354Cross-site scripting (XSS) vulnerability in the Ubercart Webform Integration module before 6.x-1.8 and 7.x before 7.x-2....
CVE-2015-4353Cross-site request forgery (CSRF) vulnerability in the Custom Sitemap module for Drupal allows remote attackers to hijac...
CVE-2015-4352Cross-site request forgery (CSRF) vulnerability in the Spider Video Player module for Drupal allows remote attackers to ...
CVE-2015-4351The Spider Video Player module for Drupal allows remote authenticated users with the "access Spider Video Player adminis...
CVE-2015-4350Multiple cross-site request forgery (CSRF) vulnerabilities in the Spider Catalog module for Drupal allow remote attacker...
CVE-2015-4349Cross-site request forgery (CSRF) vulnerability in the Spider Contacts module for Drupal allows remote attackers to hija...
CVE-2015-4348SQL injection vulnerability in the Spider Contacts module for Drupal allows remote authenticated users with the "access ...
CVE-2015-4347Cross-site scripting (XSS) vulnerability in the inLinks Integration module for Drupal allows remote attackers to inject ...
CVE-2015-4346Cross-site scripting (XSS) vulnerability in the SMS Framework module 6.x-1.x before 6.x-1.1 for Drupal, when the "Send t...
CVE-2015-4345The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for...
CVE-2015-4344The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended r...
CVE-2015-3951RLE Nova-Wind Turbine HMI devices store cleartext credentials, which allows remote attackers to obtain sensitive informa...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now