Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2014-9570

Published Jan 15, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for WordPress allow remote attackers to inject arbitrary web s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9561

Published Jan 15, 2015

Cross-site scripting (XSS) vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the post parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9560

Published Jan 15, 2015

SQL injection vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to execute arbitrary SQL commands via the post parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9308

Published Jan 15, 2015

Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote aut…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8870

Published Jan 15, 2015

Open redirect vulnerability in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin before 1.1.2 for Woltlab Burning Board 4.0 allows remote attackers to red…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8869

Published Jan 15, 2015

Multiple cross-site scripting (XSS) vulnerabilities in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin 1.x before 1.1.2 for Woltlab Burning Board 4.0 al…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8398

Published Jan 15, 2015

Multiple untrusted search path vulnerabilities in Corel FastFlick allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) igfxcmrt32.d…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-8397

Published Jan 15, 2015

Untrusted search path vulnerability in Corel VideoStudio PRO X7 or FastFlick allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse u32Z…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-8396

Published Jan 15, 2015

Untrusted search path vulnerability in Corel PDF Fusion allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll file that is…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-8395

Published Jan 15, 2015

Untrusted search path vulnerability in Corel Painter 2015 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wacommt.dll file that i…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-8394

Published Jan 15, 2015

Multiple untrusted search path vulnerabilities in Corel CAD 2014 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) FxManagedComm…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-8151

Published Jan 15, 2015

The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7957

Published Jan 15, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for re…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7956

Published Jan 15, 2015

Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0583

Published Jan 14, 2015

Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors related to file: URIs, aka Bug…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0577

Published Jan 14, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the IronPort Spam Quarantine (ISQ) page in Cisco AsyncOS, as used on the Cisco Email Security Appliance (ESA) and Content Se…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3314

Published Jan 14, 2015

Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,176-6,200 of 6,494 CVEsPage 248 of 260