2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2015-5745MEDIUM6.5Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users ...
CVE-2015-5278MEDIUM6.5The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (inf...
CVE-2015-5239MEDIUM6.5Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process c...
CVE-2015-6591MEDIUM5.5Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and ea...
CVE-2015-5072MEDIUM6.5The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote...
CVE-2015-5071MEDIUM6.5AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote auth...
CVE-2015-5484MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated use...
CVE-2015-3147MEDIUM6.5daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-up...
CVE-2015-2326MEDIUM5.5The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a ...
CVE-2015-0558MEDIUM5.3The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6, and possibly other ro...
CVE-2015-4039MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent...
CVE-2015-9540MEDIUM6.1Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
CVE-2015-5595MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack ...
CVE-2015-5593MEDIUM6.1The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attacker...
CVE-2015-5592MEDIUM6.1Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting...
CVE-2015-8313MEDIUM5.9GnuTLS incorrectly validates the first byte of padding in CBC modes
CVE-2015-3425MEDIUM6.1Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows...
CVE-2015-1853MEDIUM6.5chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows...
CVE-2015-7542MEDIUM5.3A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
CVE-2015-0837MEDIUM5.9The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information...
CVE-2015-2060MEDIUM5.3cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers t...
CVE-2015-1855MEDIUM5.9verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x ...
CVE-2015-9539MEDIUM6.1The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.
CVE-2015-9538MEDIUM6.5The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
CVE-2015-9537MEDIUM5.4The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_heig...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now