2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2015-20119MEDIUM5.4Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated at...
CVE-2015-20118MEDIUM6.1Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name paramet...
CVE-2015-20116MEDIUM6.1Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicio...
CVE-2015-20115MEDIUM6.1Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious sc...
CVE-2015-20114MEDIUM6.1Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute ar...
CVE-2015-20113MEDIUM4.3Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabi...
CVE-2015-10147MEDIUM4.9The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all v...
CVE-2015-10146MEDIUM4.9The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ver...
CVE-2015-10142MEDIUM6.9Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior t...
CVE-2015-4582MEDIUM6.1The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: C...
CVE-2015-10130MEDIUM4.3The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1...
CVE-2015-10129MEDIUM5.9A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some un...
CVE-2015-10128MEDIUM6.1A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by thi...
CVE-2015-10127MEDIUM6.1A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this...
CVE-2015-2179MEDIUM5.5The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and ...
CVE-2015-2968MEDIUM5.9LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since ...
CVE-2015-0897MEDIUM5.9LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the...
CVE-2015-6964MEDIUM5.3MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into...
CVE-2015-1390MEDIUM6.1Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.
CVE-2015-10121MEDIUM6.1A vulnerability has been found in Beeliked Microsite Plugin up to 1.0.1 on WordPress and classified as problematic. Affe...
CVE-2015-10120MEDIUM6.1A vulnerability, which was classified as problematic, was found in WDS Multisite Aggregate Plugin up to 1.0.0 on WordPre...
CVE-2015-10119MEDIUM6.1A vulnerability, which was classified as problematic, has been found in View All Posts Page Plugin up to 0.9.0 on WordPr...
CVE-2015-1313MEDIUM6.5JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the...
CVE-2015-20109MEDIUM5.5end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dep...
CVE-2015-10118MEDIUM6.1A vulnerability classified as problematic was found in cchetanonline WP-CopyProtect up to 3.0.0. This vulnerability affe...

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now