2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-20119 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated at... |
| CVE-2015-20118 | MEDIUM | 6.1 | 0.3% | Mar 16, 2026 | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name paramet... |
| CVE-2015-20116 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicio... |
| CVE-2015-20115 | MEDIUM | 6.1 | 0.3% | Mar 16, 2026 | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious sc... |
| CVE-2015-20114 | MEDIUM | 6.1 | 0.3% | Mar 16, 2026 | Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute ar... |
| CVE-2015-20113 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabi... |
| CVE-2015-10147 | MEDIUM | 4.9 | 0.3% | Oct 29, 2025 | The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all v... |
| CVE-2015-10146 | MEDIUM | 4.9 | 0.3% | Oct 29, 2025 | The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ver... |
| CVE-2015-10142 | MEDIUM | 6.9 | 0.5% | Jul 25, 2025 | Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior t... |
| CVE-2015-4582 | MEDIUM | 6.1 | 0.2% | Apr 28, 2025 | The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: C... |
| CVE-2015-10130 | MEDIUM | 4.3 | 0.2% | Mar 13, 2024 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1... |
| CVE-2015-10129 | MEDIUM | 5.9 | 0.6% | Feb 4, 2024 | A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some un... |
| CVE-2015-10128 | MEDIUM | 6.1 | 0.5% | Jan 2, 2024 | A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by thi... |
| CVE-2015-10127 | MEDIUM | 6.1 | 0.5% | Dec 26, 2023 | A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this... |
| CVE-2015-2179 | MEDIUM | 5.5 | 0.4% | Dec 12, 2023 | The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and ... |
| CVE-2015-2968 | MEDIUM | 5.9 | 0.2% | Oct 31, 2023 | LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since ... |
| CVE-2015-0897 | MEDIUM | 5.9 | 0.2% | Oct 31, 2023 | LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the... |
| CVE-2015-6964 | MEDIUM | 5.3 | 0.4% | Sep 25, 2023 | MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into... |
| CVE-2015-1390 | MEDIUM | 6.1 | 0.3% | Sep 5, 2023 | Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator. |
| CVE-2015-10121 | MEDIUM | 6.1 | 0.4% | Jul 10, 2023 | A vulnerability has been found in Beeliked Microsite Plugin up to 1.0.1 on WordPress and classified as problematic. Affe... |
| CVE-2015-10120 | MEDIUM | 6.1 | 0.5% | Jul 10, 2023 | A vulnerability, which was classified as problematic, was found in WDS Multisite Aggregate Plugin up to 1.0.0 on WordPre... |
| CVE-2015-10119 | MEDIUM | 6.1 | 0.5% | Jul 10, 2023 | A vulnerability, which was classified as problematic, has been found in View All Posts Page Plugin up to 0.9.0 on WordPr... |
| CVE-2015-1313 | MEDIUM | 6.5 | 0.5% | Jun 29, 2023 | JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the... |
| CVE-2015-20109 | MEDIUM | 5.5 | 0.3% | Jun 25, 2023 | end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dep... |
| CVE-2015-10118 | MEDIUM | 6.1 | 0.5% | Jun 12, 2023 | A vulnerability classified as problematic was found in cchetanonline WP-CopyProtect up to 3.0.0. This vulnerability affe... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now