2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-1396HIGH7.5A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files...
CVE-2015-3140HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Sy...
CVE-2015-3167HIGH7.5contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x be...
CVE-2015-9498HIGH8.8The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
CVE-2015-9497HIGH8.8The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-i...
CVE-2015-9496HIGH8.8The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring...
CVE-2015-9492HIGH7.5The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sens...
CVE-2015-9491HIGH7.5The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sen...
CVE-2015-9490HIGH7.5The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive in...
CVE-2015-9489HIGH7.5The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sens...
CVE-2015-9488HIGH7.5The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attac...
CVE-2015-9487HIGH7.5The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sen...
CVE-2015-9486HIGH7.5The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensi...
CVE-2015-9485HIGH7.5The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remot...
CVE-2015-9484HIGH7.5The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obt...
CVE-2015-9483HIGH7.5The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remot...
CVE-2015-9482HIGH7.5The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to ob...
CVE-2015-9481HIGH7.5The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive ...
CVE-2015-9480HIGH7.5The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
CVE-2015-9477HIGH8.8The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
CVE-2015-9476HIGH8.8The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
CVE-2015-9475HIGH8.8The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
CVE-2015-9474HIGH8.8The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
CVE-2015-9473HIGH7.5The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo...
CVE-2015-9470HIGH7.5The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now