2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2015-3166CRITICAL9.8The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, a...
CVE-2015-8980CRITICAL9.8The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbi...
CVE-2015-0270CRITICAL9.8Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
CVE-2015-9499CRITICAL9.8The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
CVE-2015-9479CRITICAL9.8The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request ...
CVE-2015-9471CRITICAL9.8The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
CVE-2015-9467CRITICAL9.8The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parame...
CVE-2015-9466CRITICAL9.8The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTT...
CVE-2015-9452CRITICAL9.8The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?pag...
CVE-2015-9451CRITICAL9.8The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p...
CVE-2015-9450CRITICAL9.8The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p...
CVE-2015-9435CRITICAL9.8The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
CVE-2015-9333CRITICAL9.8The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
CVE-2015-9324CRITICAL9.8The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
CVE-2015-9323CRITICAL9.8The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
CVE-2015-9298CRITICAL9.8The events-manager plugin before 5.6 for WordPress has code injection.
CVE-2015-9280CRITICAL10MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
CVE-2015-9266CRITICAL9.8The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an...
CVE-2015-9244CRITICAL9.8Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to...
CVE-2015-5172CRITICAL9.8Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1....
CVE-2015-5171CRITICAL9.8The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Fo...
CVE-2015-1187CRITICAL9.8The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr...
CVE-2015-5224CRITICAL9.8The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name coll...
CVE-2015-2857CRITICAL9.8Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach...
CVE-2015-2310CRITICAL9.1Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to c...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now