2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2015-0270CRITICAL9.8Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
CVE-2015-9499CRITICAL9.8The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
CVE-2015-9479CRITICAL9.8The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request ...
CVE-2015-9471CRITICAL9.8The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
CVE-2015-9467CRITICAL9.8The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parame...
CVE-2015-9466CRITICAL9.8The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTT...
CVE-2015-9452CRITICAL9.8The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?pag...
CVE-2015-9451CRITICAL9.8The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p...
CVE-2015-9450CRITICAL9.8The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p...
CVE-2015-9435CRITICAL9.8The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
CVE-2015-9333CRITICAL9.8The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
CVE-2015-9324CRITICAL9.8The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
CVE-2015-9323CRITICAL9.8The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
CVE-2015-9298CRITICAL9.8The events-manager plugin before 5.6 for WordPress has code injection.
CVE-2015-9280CRITICAL10MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
CVE-2015-9244CRITICAL9.8Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to...
CVE-2015-5172CRITICAL9.8Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1....
CVE-2015-5171CRITICAL9.8The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Fo...
CVE-2015-1187CRITICAL9.8The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr...
CVE-2015-5224CRITICAL9.8The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name coll...
CVE-2015-2857CRITICAL9.8Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach...
CVE-2015-2310CRITICAL9.1Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to c...
CVE-2015-7871CRITICAL9.8Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authen...
CVE-2015-7853CRITICAL9.8The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attacker...
CVE-2015-7705CRITICAL9.8The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified ...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now