2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2015-10143CRITICAL9.8The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio...
CVE-2015-10141CRITICAL9.3An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging e...
CVE-2015-10137CRITICAL9.8The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi...
CVE-2015-10138CRITICAL9.8The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2015-10135CRITICAL9.8The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2015-0843CRITICAL9.8yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.
CVE-2015-0842CRITICAL9.8yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.
CVE-2015-20111CRITICAL9.8miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values...
CVE-2015-10126CRITICAL9.8A vulnerability classified as critical was found in Easy2Map Photos Plugin 1.0.1 on WordPress. This vulnerability affect...
CVE-2015-10124CRITICAL9.8A vulnerability was found in Most Popular Posts Widget Plugin up to 0.8 on WordPress. It has been classified as critical...
CVE-2015-5467CRITICAL9.8web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in...
CVE-2015-10122CRITICAL9.8A vulnerability was found in wp-donate Plugin up to 1.4 on WordPress. It has been classified as critical. This affects a...
CVE-2015-10111CRITICAL9.8A vulnerability was found in Watu Quiz Plugin up to 2.6.7 on WordPress. It has been rated as critical. This issue affect...
CVE-2015-20108CRITICAL9.8xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared st...
CVE-2015-10105CRITICAL9.8A vulnerability, which was classified as critical, was found in IP Blacklist Cloud Plugin up to 3.42 on WordPress. This ...
CVE-2015-10100CRITICAL9.8A vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10 on WordPress. T...
CVE-2015-10099CRITICAL9.8A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This a...
CVE-2015-10097CRITICAL9.8A vulnerability was found in grinnellplans-php up to 3.0. It has been declared as critical. Affected by this vulnerabili...
CVE-2015-10086CRITICAL9.8A vulnerability, which was classified as critical, was found in OpenCycleCompass server-php. Affected is an unknown func...
CVE-2015-10084CRITICAL9.8A vulnerability was found in irontec klear-library chloe and classified as critical. Affected by this issue is the funct...
CVE-2015-10083CRITICAL9.8A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability i...
CVE-2015-10082CRITICAL9.8A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_x...
CVE-2015-10077CRITICAL9.8A vulnerability was found in webbuilders-group silverstripe-kapost-bridge 0.3.3. It has been declared as critical. Affec...
CVE-2015-10076CRITICAL9.8A vulnerability was found in dimtion Shaarlier up to 1.2.2. It has been declared as critical. Affected by this vulnerabi...
CVE-2015-10073CRITICAL9.6A vulnerability, which was classified as problematic, was found in tinymighty WikiSEO 1.2.1 on MediaWiki. This affects t...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now