Vulnerabilities (CVE)

Total 398094 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9308 1 Weplugins 1 Wp Maps 2026-06-17 6.8 MEDIUM 8.8 HIGH
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
CVE-2015-9307 1 Weplugins 1 Wp Maps 2026-06-17 6.8 MEDIUM 8.8 HIGH
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
CVE-2015-9306 1 Smackcoders 1 Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
CVE-2015-9305 1 Weplugins 1 Wp Maps 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
CVE-2015-9304 1 Ultimatemember 1 Ultimate Member 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
CVE-2015-9303 1 Simplesharebuttons 1 Simple Share Buttons Adder 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
CVE-2015-9302 1 Simple Fields Project 1 Simple Fields 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The simple-fields plugin before 1.4.11 for WordPress has XSS.
CVE-2015-9301 1 W3eden 1 Live Forms 2026-06-17 7.5 HIGH 9.8 CRITICAL
The liveforms plugin before 3.2.0 for WordPress has SQL injection.
CVE-2015-9300 1 Pixelite 1 Events Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
CVE-2015-9299 1 Pixelite 1 Events Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
CVE-2015-9298 1 Pixelite 1 Events Manager 2026-06-17 7.5 HIGH 9.8 CRITICAL
The events-manager plugin before 5.6 for WordPress has code injection.
CVE-2015-9297 1 Pixelite 1 Events Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.6 for WordPress has XSS.
CVE-2015-9296 1 Never5 1 Download Monitor 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
CVE-2015-9295 1 Bestwebsoft 1 Contact Form 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
CVE-2015-9294 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
CVE-2015-9293 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
CVE-2015-9292 1 6kbbs 1 6kbbs 2026-06-17 6.8 MEDIUM 8.8 HIGH
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
CVE-2015-9291 1 Cpanel 1 Cpanel 2026-06-17 5.0 MEDIUM 7.5 HIGH
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
CVE-2015-9290 1 Freetype 1 Freetype 2026-06-17 7.5 HIGH 9.8 CRITICAL
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.
CVE-2015-9289 1 Linux 1 Linux Kernel 2026-06-17 4.9 MEDIUM 5.5 MEDIUM
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.