2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-3419 | — | — | 1.0% | Sep 19, 2017 | vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages... |
| CVE-2015-3299 | — | — | 1.8% | Sep 19, 2017 | Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote atta... |
| CVE-2015-1864 | — | — | 0.9% | Sep 19, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote a... |
| CVE-2015-1854 | — | — | 2.1% | Sep 19, 2017 | 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entrie... |
| CVE-2015-0689 | — | — | 1.4% | Sep 19, 2017 | Cisco Cloud Web Security before 3.0.1.7 allows remote attackers to bypass intended filtering protection mechanisms by le... |
| CVE-2015-1527 | — | — | 0.2% | Sep 15, 2017 | Integer overflow in IAudioPolicyService.cpp in Android allows local users to gain privileges via a crafted application, ... |
| CVE-2015-0110 | — | — | 1.0% | Sep 15, 2017 | IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remo... |
| CVE-2015-0166 | — | — | — | Sep 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-0165 | — | — | — | Sep 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-0164 | — | — | — | Sep 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2015-7553 | — | — | 0.2% | Sep 14, 2017 | Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_l... |
| CVE-2015-7880 | — | — | 1.4% | Sep 13, 2017 | The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event regis... |
| CVE-2015-5206 | — | — | 2.4% | Sep 13, 2017 | Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unkn... |
| CVE-2015-5168 | — | — | 2.4% | Sep 13, 2017 | Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown imp... |
| CVE-2015-2750 | — | — | 1.4% | Sep 13, 2017 | Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote att... |
| CVE-2015-2749 | — | — | 1.5% | Sep 13, 2017 | Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to a... |
| CVE-2015-9230 | MEDIUM | 4.8 | 1.6% | Sep 12, 2017 | In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPres... |
| CVE-2015-9229 | MEDIUM | 4.8 | 1.0% | Sep 12, 2017 | In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for ... |
| CVE-2015-9228 | — | — | 3.7% | Sep 12, 2017 | In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via... |
| CVE-2015-9227 | — | — | 2.5% | Sep 11, 2017 | PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCa... |
| CVE-2015-9226 | — | — | 2.0% | Sep 11, 2017 | Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands... |
| CVE-2015-8354 | — | — | 2.1% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remo... |
| CVE-2015-8353 | — | — | 2.1% | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in the Role Scoper plugin before 1.3.67 for WordPress allows remote attackers t... |
| CVE-2015-8351 | — | — | 37.0% | Sep 11, 2017 | PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ... |
| CVE-2015-8350 | — | — | 2.6% | Sep 11, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remot... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now