Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2014-100027

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in the WP SlimStat plugin before 3.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100025

Published Jan 13, 2015

Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authentication of administrators for reque…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100024

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in Seo Panel before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100023

Published Jan 13, 2015

Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100022

Published Jan 13, 2015

SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-ad…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100021

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in symfony/web/index.php/pim/viewEmployeeList in OrangeHRM before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100020

Published Jan 13, 2015

SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatI…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100019

Published Jan 13, 2015

SQL injection vulnerability in the LTree converter in Pomm before 1.1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100018

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in the Unconfirmed plugin before 1.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100017

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web script or HTML via the message field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100016

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in photocrati-gallery/ecomm-sizes.php in the Photocrati theme for WordPress allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100015

Published Jan 13, 2015

Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a .. (dot dot) in the filename in a f…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100014

Published Jan 13, 2015

Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to execute arbitrary code via a long string in a (1) 2001, (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100013

Published Jan 13, 2015

Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject or (2) Message field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100012

Published Jan 13, 2015

SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100011

Published Jan 13, 2015

SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10030

Published Jan 13, 2015

Open redirect vulnerability in forums/login.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10029

Published Jan 13, 2015

SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10028

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in D-Link DAP-1360 router with firmware 2.5.4 and later allows remote attackers to inject arbitrary web script or HTML via the res_buf par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10027

Published Jan 13, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 router with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspeci…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10026

Published Jan 13, 2015

index.cgi in D-Link DAP-1360 with firmware 2.5.4 and earlier allows remote attackers to bypass authentication and obtain sensitive information by setting the client_login cookie t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10025

Published Jan 13, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified us…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10023

Published Jan 13, 2015

Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,251-6,275 of 6,494 CVEsPage 251 of 260