2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2015-10148HIGH8.8Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical...
CVE-2015-20117HIGH8.8Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated a...
CVE-2015-10145HIGH8.8Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utilit...
CVE-2015-10144HIGH8.8The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sa...
CVE-2015-10140HIGH8.8The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authentic...
CVE-2015-10139HIGH8.8The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import...
CVE-2015-10136HIGH7.5The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' p...
CVE-2015-10134HIGH7.5The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10...
CVE-2015-10133HIGH7.2The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 vi...
CVE-2015-2079HIGH8.8Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the t...
CVE-2015-10123HIGH8.8An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user...
CVE-2015-8314HIGH7.5The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain...
CVE-2015-20110HIGH7.5JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that s...
CVE-2015-10125HIGH8.8A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This aff...
CVE-2015-8371HIGH8.8Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-c...
CVE-2015-2202HIGH7.2Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the und...
CVE-2015-2201HIGH7.2Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by ad...
CVE-2015-1391HIGH8.8Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.
CVE-2015-10116HIGH8.8A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPres...
CVE-2015-10109HIGH8.8A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. It has been rated as problemati...
CVE-2015-10108HIGH8.8A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as p...
CVE-2015-10106HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in mback2k mh_httpbl Extension up to 1....
CVE-2015-10096HIGH8.1A vulnerability, which was classified as critical, was found in Zarthus IRC Twitter Announcer Bot up to 1.1.0. This affe...
CVE-2015-10087HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and c...
CVE-2015-10091HIGH7.2A vulnerability has been found in ByWater Solutions bywater-koha-xslt and classified as critical. This vulnerability aff...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now