CVE-2015-9000 to CVE-2015-9999
112 CVEs with public proof-of-concept exploits.
- CVE-2015-90981 PoCIn Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in…
- CVE-2015-91011 PoCThe fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4 and 3.99.5…
- CVE-2015-92221 PoCIn Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD…
- CVE-2015-92263 PoCsMultiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download…
- CVE-2015-92273 PoCsPHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows…
- CVE-2015-92291 PoCIn the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote…
- CVE-2015-92304 PoCsIn the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPress, XSS is possible…
- CVE-2015-92321 PoCThe Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent.…
- CVE-2015-92355 PoCsIn jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an…
- CVE-2015-92391 PoCansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
- CVE-2015-92451 PoCInsecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary…
- CVE-2015-92513 PoCsjQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType…
- CVE-2015-92531 PoCAn issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a…
- CVE-2015-92601 PoCAn issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as…
- CVE-2015-92619 PoCshuft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application…
- CVE-2015-92634 PoCsAn issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to…
- CVE-2015-92664 PoCsUbiquiti airOS HTTP(S) unauthenticated arbitrary file upload
- CVE-2015-92691 PoCThe export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote…
- CVE-2015-92721 PoCThe videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because…
- CVE-2015-92851 PoCesoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.
- CVE-2015-92862 PoCsControllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
- CVE-2015-93121 PoCThe newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
- CVE-2015-93161 PoCThe wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via…
- CVE-2015-93232 PoCsThe 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
- CVE-2015-93311 PoCThe wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
- CVE-2015-93571 PoCThe akismet plugin before 3.1.5 for WordPress has XSS.
- CVE-2015-93831 PoCFreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
- CVE-2015-93861 PoCThe mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.
- CVE-2015-93871 PoCThe mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.
- CVE-2015-93881 PoCThe mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.
- CVE-2015-93891 PoCThe mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.
- CVE-2015-93921 PoCThe users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter.
- CVE-2015-94031 PoCThe neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS.
- CVE-2015-94041 PoCThe neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS.
- CVE-2015-94063 PoCsDirectory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a ..…
- CVE-2015-94071 PoCThe xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS.
- CVE-2015-94081 PoCThe xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.
- CVE-2015-94091 PoCThe alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
- CVE-2015-94101 PoCThe Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
- CVE-2015-94121 PoCThe Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.
- CVE-2015-94132 PoCsThe eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title…
- CVE-2015-94142 PoCsThe wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.
- CVE-2015-94152 PoCsThe bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.
- CVE-2015-94161 PoCThe sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.
- CVE-2015-94171 PoCThe testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
- CVE-2015-94181 PoCThe Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.
- CVE-2015-94191 PoCThe captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section.
- CVE-2015-94201 PoCThe soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.
- CVE-2015-94211 PoCThe olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup…
- CVE-2015-94221 PoCThe PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via…
- CVE-2015-94231 PoCThe PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via…
- CVE-2015-94241 PoCThe multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the…
- CVE-2015-94251 PoCThe social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the…
- CVE-2015-94261 PoCThe manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the…
- CVE-2015-94272 PoCsThe googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID…
- CVE-2015-94281 PoCThe wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name,…
- CVE-2015-94291 PoCThe yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the…
- CVE-2015-94301 PoCThe crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header.
- CVE-2015-94311 PoCThe qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x…
- CVE-2015-94321 PoCThe alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the…
- CVE-2015-94331 PoCThe wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr,…
- CVE-2015-94341 PoCThe kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the…
- CVE-2015-94361 PoCThe dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id…
- CVE-2015-94371 PoCThe dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config…
- CVE-2015-94401 PoCThe monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.
- CVE-2015-94411 PoCThe bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.
- CVE-2015-94421 PoCThe avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.
- CVE-2015-94431 PoCThe accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via…
- CVE-2015-94441 PoCThe altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/captcha/index.php/…
- CVE-2015-94451 PoCThe unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a…
- CVE-2015-94461 PoCThe unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
- CVE-2015-94471 PoCThe unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
- CVE-2015-94491 PoCThe microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=microblogposter.php…
- CVE-2015-94511 PoCThe plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the…
- CVE-2015-94521 PoCThe nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main…
- CVE-2015-94531 PoCThe broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.
- CVE-2015-94541 PoCThe smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id…
- CVE-2015-94561 PoCThe orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the…
- CVE-2015-94631 PoCThe s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the…
- CVE-2015-94641 PoCThe s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the…
- CVE-2015-94691 PoCThe content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.
- CVE-2015-94701 PoCThe history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
- CVE-2015-94731 PoCThe estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.
- CVE-2015-94741 PoCThe Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
- CVE-2015-94751 PoCThe Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
- CVE-2015-94791 PoCThe ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to…
- CVE-2015-94802 PoCsThe RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
- CVE-2015-94811 PoCThe ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such…
- CVE-2015-94821 PoCThe ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive…
- CVE-2015-94831 PoCThe ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to…
- CVE-2015-94841 PoCThe ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive…
- CVE-2015-94851 PoCThe ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to…
- CVE-2015-94861 PoCThe ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information…
- CVE-2015-94871 PoCThe ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information…
- CVE-2015-94881 PoCThe ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain…
- CVE-2015-94891 PoCThe ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information…
- CVE-2015-94901 PoCThe ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as…
- CVE-2015-94911 PoCThe ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information…
- CVE-2015-94921 PoCThe ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information…
- CVE-2015-94941 PoCThe indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.
- CVE-2015-94951 PoCThe syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.
- CVE-2015-94962 PoCsThe freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
- CVE-2015-94971 PoCThe ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
- CVE-2015-94993 PoCsThe Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
- CVE-2015-95001 PoCThe Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
- CVE-2015-95041 PoCThe weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter.
- CVE-2015-95372 PoCsThe NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth,…
- CVE-2015-95385 PoCsThe NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
- CVE-2015-95392 PoCsThe Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.
- CVE-2015-95441 PoCAn issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not…
- CVE-2015-95451 PoCAn issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any…
- CVE-2015-95492 PoCsA reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to…