2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-3384Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for D...
CVE-2015-3383Open redirect vulnerability in the Node basket module for Drupal allows remote attackers to redirect users to arbitrary ...
CVE-2015-3382Multiple cross-site request forgery (CSRF) vulnerabilities in the Node basket module for Drupal allow remote attackers t...
CVE-2015-3381Cross-site scripting (XSS) vulnerability in the Node basket module for Drupal allows remote authenticated users to injec...
CVE-2015-3380Multiple cross-site request forgery (CSRF) vulnerabilities in the Feature Set module for Drupal allow remote attackers t...
CVE-2015-3379The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restr...
CVE-2015-3378Open redirect vulnerability in the Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for...
CVE-2015-3376Cross-site scripting (XSS) vulnerability in the Quizzler module before 7-x.1.16 for Drupal allows remote authenticated u...
CVE-2015-3375Cross-site request forgery (CSRF) vulnerability in the Shibboleth Authentication module before 6.x-4.1 and 7.x-4.x befor...
CVE-2015-3374Multiple cross-site request forgery (CSRF) vulnerabilities in the Corner module for Drupal allow remote attackers to hij...
CVE-2015-3373The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which...
CVE-2015-3372Cross-site scripting (XSS) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote authenticated...
CVE-2015-3371Open redirect vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to redirect user...
CVE-2015-3370Cross-site request forgery (CSRF) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attack...
CVE-2015-3369Cross-site scripting (XSS) vulnerability in the Taxonews module before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal all...
CVE-2015-3368Cross-site scripting (XSS) vulnerability in the administration user interface in the Classified Ads module before 6.x-3....
CVE-2015-3367Multiple cross-site request forgery (CSRF) vulnerabilities in the Patterns module before 7.x-2.2 for Drupal allow remote...
CVE-2015-3366Cross-site request forgery (CSRF) vulnerability in the Alfresco module before 6.x-1.3 for Drupal allows remote attackers...
CVE-2015-3365Cross-site scripting (XSS) vulnerability in the nodeauthor module for Drupal allows remote authenticated users to inject...
CVE-2015-3364Cross-site scripting (XSS) vulnerability in the Content Analysis module before 6.x-1.7 for Drupal allows remote attacker...
CVE-2015-3363Cross-site request forgery (CSRF) vulnerability in the Contact Form Fields module before 6.x-2.3 for Drupal allows remot...
CVE-2015-3362Cross-site scripting (XSS) vulnerability in the Video module before 7.x-2.11 for Drupal, when using the video WYSIWYG pl...
CVE-2015-3361Cross-site scripting (XSS) vulnerability in the Linkit module before 7.x-2.7 and 7.x-3.x before 7.x-3.3 for Drupal, when...
CVE-2015-3360Cross-site scripting (XSS) vulnerability in the Term Merge module before 7.x-1.2 for Drupal allows remote authenticated ...
CVE-2015-3359Multiple cross-site scripting (XSS) vulnerabilities in the Room Reservations module before 7.x-1.1 for Drupal allow remo...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now