2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-5342 | — | — | 1.3% | Feb 22, 2016 | The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remot... |
| CVE-2015-5341 | — | — | 1.3% | Feb 22, 2016 | mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availabil... |
| CVE-2015-5340 | — | — | 1.3% | Feb 22, 2016 | Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badg... |
| CVE-2015-5339 | — | — | 1.3% | Feb 22, 2016 | The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.... |
| CVE-2015-5338 | — | — | 0.8% | Feb 22, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2... |
| CVE-2015-5337 | — | — | 1.1% | Feb 22, 2016 | Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the av... |
| CVE-2015-5336 | — | — | 0.9% | Feb 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, ... |
| CVE-2015-5335 | — | — | 0.7% | Feb 22, 2016 | Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x befor... |
| CVE-2015-5332 | — | — | 1.7% | Feb 22, 2016 | Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk cons... |
| CVE-2015-5331 | — | — | 1.3% | Feb 22, 2016 | Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows... |
| CVE-2015-5272 | — | — | 1.5% | Feb 22, 2016 | The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveragi... |
| CVE-2015-5269 | — | — | 1.2% | Feb 22, 2016 | Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x befo... |
| CVE-2015-5268 | — | — | 1.6% | Feb 22, 2016 | The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandle... |
| CVE-2015-5267 | — | — | 2.4% | Feb 22, 2016 | lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on th... |
| CVE-2015-5266 | — | — | 1.6% | Feb 22, 2016 | The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.... |
| CVE-2015-5265 | — | — | 1.5% | Feb 22, 2016 | The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not co... |
| CVE-2015-5264 | — | — | 1.4% | Feb 22, 2016 | The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remot... |
| CVE-2015-3275 | — | — | 1.5% | Feb 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.... |
| CVE-2015-3274 | — | — | 1.5% | Feb 22, 2016 | Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11,... |
| CVE-2015-3273 | — | — | 1.5% | Feb 22, 2016 | mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before auth... |
| CVE-2015-3272 | — | — | 1.8% | Feb 22, 2016 | Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.... |
| CVE-2015-7425 | — | — | 3.9% | Feb 21, 2016 | The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Pro... |
| CVE-2015-7769 | — | — | 1.1% | Feb 19, 2016 | baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors. |
| CVE-2015-3825 | — | — | — | Feb 18, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-3837. Reason: This candidate is a reservation du... |
| CVE-2015-8151 | — | — | 1.9% | Feb 18, 2016 | Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now