Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2015-1057

Published Jan 16, 2015

Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1055

Published Jan 16, 2015

SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox ac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1054

Published Jan 16, 2015

Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the Game Content fiel…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-1053

Published Jan 16, 2015

Cross-site scripting (XSS) vulnerability in the administrative backend in Croogo before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9600

Published Jan 16, 2015

Untrusted search path vulnerability in Macroplant iExplorer 3.6.3.0 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse itunesmobiled…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9599

Published Jan 16, 2015

Cross-site scripting (XSS) vulnerability in the filemanager in b2evolution before 5.2.1 allows remote attackers to inject arbitrary web script or HTML via the fm_filter parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0591

Published Jan 15, 2015

Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to cause a denial of service (daemon hang and GUI outage) via a flood of malformed TCP packets, aka B…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0588

Published Jan 15, 2015

Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authentication of arbitrary users, a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8904

Published Jan 15, 2015

lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8034

Published Jan 15, 2015

Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8022

Published Jan 15, 2015

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Identity Services Engine allow remote attackers to inject arbitrary web script or HTML via input to unspecified web pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7881

Published Jan 15, 2015

Cross-site scripting (XSS) vulnerability in the server in HP Insight Control allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1052

Published Jan 15, 2015

Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web script or HTML via the result parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1051

Published Jan 15, 2015

Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and c…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1050

Published Jan 15, 2015

Cross-site scripting (XSS) vulnerability in F5 BIG-IP Application Security Manager (ASM) before 11.6 allows remote attackers to inject arbitrary web script or HTML via the Respons…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1041

Published Jan 15, 2015

Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1040

Published Jan 15, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in BEdita 3.4.0 allow remote authenticated users to inject arbitrary web script or HTML via the (…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-1039

Published Jan 15, 2015

Cross-site scripting (XSS) vulnerability in user/login.phtml in ZF-Commons ZfcUser before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the redirect par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0552

Published Jan 15, 2015

Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9595

Published Jan 15, 2015

Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of service or possibly execute arbitr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9594

Published Jan 15, 2015

Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of service or possibly execute arbitr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9593

Published Jan 15, 2015

Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9587

Published Jan 15, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,151-6,175 of 6,494 CVEsPage 247 of 260