2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-9307 | HIGH | 8.8 | 0.7% | Aug 14, 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. |
| CVE-2015-7882 | HIGH | 8.1 | 1.8% | Jul 19, 2019 | Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to g... |
| CVE-2015-9284 | HIGH | 8.8 | 1.6% | Apr 26, 2019 | The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as ... |
| CVE-2015-1341 | HIGH | 7.4 | 0.4% | Apr 22, 2019 | Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and t... |
| CVE-2015-1340 | HIGH | 7 | 0.9% | Apr 22, 2019 | LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the... |
| CVE-2015-9268 | HIGH | 7.8 | 1.5% | Oct 1, 2018 | Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, t... |
| CVE-2015-9239 | HIGH | 7.5 | 1.2% | May 31, 2018 | ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in. |
| CVE-2015-6926 | HIGH | 7.5 | 1.1% | Jan 19, 2018 | The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate... |
| CVE-2015-7529 | HIGH | 7.8 | 0.4% | Nov 6, 2017 | sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a sy... |
| CVE-2015-5173 | HIGH | 8.8 | 1.0% | Oct 24, 2017 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.... |
| CVE-2015-5170 | HIGH | 8.8 | 0.8% | Oct 24, 2017 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.... |
| CVE-2015-7715 | HIGH | 8.8 | 3.1% | Oct 18, 2017 | Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows ... |
| CVE-2015-7714 | HIGH | 7.2 | 2.2% | Oct 18, 2017 | Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm... |
| CVE-2015-7504 | HIGH | 8.8 | 0.6% | Oct 16, 2017 | Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cau... |
| CVE-2015-1429 | HIGH | 7.5 | 2.0% | Oct 6, 2017 | Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit all... |
| CVE-2015-9233 | HIGH | 8.8 | 1.0% | Sep 30, 2017 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with result... |
| CVE-2015-5184 | HIGH | 7.5 | 1.2% | Sep 25, 2017 | Console: CORS headers set to allow all in Red Hat AMQ. |
| CVE-2015-5183 | HIGH | 7.5 | 2.2% | Sep 25, 2017 | Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ. |
| CVE-2015-5182 | HIGH | 8.8 | 0.6% | Sep 25, 2017 | Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ. |
| CVE-2015-5237 | HIGH | 8.8 | 5.1% | Sep 25, 2017 | protobuf allows remote authenticated attackers to cause a heap-based buffer overflow. |
| CVE-2015-8559 | HIGH | 7.5 | 1.9% | Sep 21, 2017 | The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/... |
| CVE-2015-5395 | HIGH | 8.8 | 0.9% | Sep 20, 2017 | Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0. |
| CVE-2015-3890 | HIGH | 7.5 | 1.1% | Sep 20, 2017 | Use-after-free vulnerability in Open Litespeed before 1.3.10. |
| CVE-2015-4075 | HIGH | 8.1 | 7.4% | Sep 20, 2017 | The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted ... |
| CVE-2015-7294 | HIGH | 7.5 | 2.1% | Sep 6, 2017 | ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username. |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now