Vulnerabilities (CVE)

Total 396934 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-1000009 1 Google-adsense-and-hotel-booking Project 1 Google-adsense-and-hotel-booking 2026-06-17 6.4 MEDIUM 9.1 CRITICAL
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
CVE-2015-1000008 1 Mp3-jplayer Project 1 Mp3-jplayer 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2
CVE-2015-1000007 1 Wptf-image-gallery Project 1 Wptf-image-gallery 2026-06-17 5.0 MEDIUM 7.5 HIGH
Remote file download vulnerability in wptf-image-gallery v1.03
CVE-2015-1000006 1 Recent-backups Project 1 Recent-backups 2026-06-17 5.0 MEDIUM 7.5 HIGH
Remote file download vulnerability in recent-backups v0.7 wordpress plugin
CVE-2015-1000005 1 Candidate-application-form Project 1 Candidate-application-form 2026-06-17 5.0 MEDIUM 7.5 HIGH
Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin
CVE-2015-1000004 1 Filedownload Project 1 Filedownload 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS in filedownload v1.4 wordpress plugin
CVE-2015-1000003 1 Filedownload Project 1 Filedownload 2026-06-17 7.5 HIGH 9.8 CRITICAL
Blind SQL Injection in filedownload v1.4 wordpress plugin
CVE-2015-1000002 1 Filedownload Project 1 Filedownload 2026-06-17 5.8 MEDIUM 8.2 HIGH
Open Proxy in filedownload v1.4 wordpress plugin
CVE-2015-1000001 1 Fast-image-adder Project 1 Fast-image-adder 2026-06-17 5.0 MEDIUM 9.8 CRITICAL
Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin
CVE-2015-1000000 1 Mailcwp Project 1 Mailcwp 2026-06-17 5.0 MEDIUM 9.8 CRITICAL
Remote file upload vulnerability in mailcwp v1.99 wordpress plugin
CVE-2015-0999 2 Aveva, Schneider-electric 2 Aveva Edge, Wonderware Intouch 2014 2026-06-17 2.1 LOW N/A
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file.
CVE-2015-0998 2 Aveva, Schneider-electric 2 Aveva Edge, Wonderware Intouch 2014 2026-06-17 3.3 LOW N/A
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
CVE-2015-0997 2 Aveva, Schneider-electric 2 Aveva Edge, Wonderware Intouch 2014 2026-06-17 5.0 MEDIUM N/A
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.
CVE-2015-0996 2 Aveva, Schneider-electric 2 Aveva Edge, Wonderware Intouch 2014 2026-06-17 2.1 LOW N/A
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.
CVE-2015-0995 1 Inductiveautomation 1 Ignition 2026-06-17 5.0 MEDIUM N/A
Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack.
CVE-2015-0994 1 Inductiveautomation 1 Ignition 2026-06-17 4.0 MEDIUM N/A
Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests.
CVE-2015-0993 1 Inductiveautomation 1 Ignition 2026-06-17 6.4 MEDIUM N/A
Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
CVE-2015-0992 1 Inductiveautomation 1 Ignition 2026-06-17 2.1 LOW N/A
Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors.
CVE-2015-0991 1 Inductiveautomation 1 Ignition 2026-06-17 5.0 MEDIUM N/A
Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception, as demonstrated by pathname information.
CVE-2015-0990 1 Ecava 1 Integraxor 2026-06-17 4.4 MEDIUM N/A
Untrusted search path vulnerability in Ecava IntegraXor SCADA Server before 4.2.4488 allows local users to gain privileges via a renamed DLL in the default install directory.