2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2015-9294The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg ...
CVE-2015-9293The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
CVE-2015-9303The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
CVE-2015-9306The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
CVE-2015-9305The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg()...
CVE-2015-92926kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
CVE-2015-9291cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-12...
CVE-2015-9290In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no...
CVE-2015-9288The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online ser...
CVE-2015-6253edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
CVE-2015-5601edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles ....
CVE-2015-3907CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
CVE-2015-7609Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbr...
CVE-2015-9287Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification fiel...
CVE-2015-1006A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9....
CVE-2015-9286Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
CVE-2015-9285esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.
CVE-2015-5462AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dash...
CVE-2015-5384AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier is vulnerable to a Session Fixation attack.
CVE-2015-5463AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and ea...
CVE-2015-5606Vordel XML Gateway (acquired by Axway) version 7.2.2 could allow remote attackers to cause a denial of service via a spe...
CVE-2015-1014A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory...
CVE-2015-1012Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, v...
CVE-2015-1007A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe...
CVE-2015-3956Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infu...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now