2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-9313The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
CVE-2015-9312The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
CVE-2015-9311The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
CVE-2015-9302MEDIUM6.1The simple-fields plugin before 1.4.11 for WordPress has XSS.
CVE-2015-9301The liveforms plugin before 3.2.0 for WordPress has SQL injection.
CVE-2015-9300The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
CVE-2015-9299The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
CVE-2015-9298CRITICAL9.8The events-manager plugin before 5.6 for WordPress has code injection.
CVE-2015-9297MEDIUM6.1The events-manager plugin before 5.6 for WordPress has XSS.
CVE-2015-9296The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
CVE-2015-9295The contact-form-plugin plugin before 3.96 for WordPress has XSS.
CVE-2015-9294The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg ...
CVE-2015-9293The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
CVE-2015-9304MEDIUM6.1The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
CVE-2015-9303The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
CVE-2015-9306The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
CVE-2015-9305The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg()...
CVE-2015-92926kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
CVE-2015-9291cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-12...
CVE-2015-7559LOW2.7It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection c...
CVE-2015-5297MEDIUM6.7An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. ...
CVE-2015-9290In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no...
CVE-2015-9288The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online ser...
CVE-2015-6960MEDIUM6.1edx-platform before 2015-09-17 allows XSS via a team name.
CVE-2015-6253edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now