2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-9307HIGH8.8The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
CVE-2015-7882HIGH8.1Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to g...
CVE-2015-9284HIGH8.8The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as ...
CVE-2015-1341HIGH7.4Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and t...
CVE-2015-1340HIGH7LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the...
CVE-2015-9268HIGH7.8Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, t...
CVE-2015-9239HIGH7.5ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
CVE-2015-6926HIGH7.5The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate...
CVE-2015-7529HIGH7.8sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a sy...
CVE-2015-5173HIGH8.8Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1....
CVE-2015-5170HIGH8.8Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1....
CVE-2015-7715HIGH8.8Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows ...
CVE-2015-7714HIGH7.2Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm...
CVE-2015-7504HIGH8.8Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cau...
CVE-2015-1429HIGH7.5Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit all...
CVE-2015-9233HIGH8.8The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with result...
CVE-2015-5184HIGH7.5Console: CORS headers set to allow all in Red Hat AMQ.
CVE-2015-5183HIGH7.5Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
CVE-2015-5182HIGH8.8Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
CVE-2015-5237HIGH8.8protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
CVE-2015-8559HIGH7.5The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/...
CVE-2015-5395HIGH8.8Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
CVE-2015-3890HIGH7.5Use-after-free vulnerability in Open Litespeed before 1.3.10.
CVE-2015-4075HIGH8.1The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted ...
CVE-2015-7294HIGH7.5ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username.

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now