Vulnerability threat dossier

CVE-2015-7501

Vendor unknownProduct mapping pending

Metadata pending authoritative retrieval.

VTP deterministic threat58.1of 100 · CVSS excluded

VTP analyst assessment

Public exploit tooling with reported active exploitation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence86%
Public exploitation · VTP factCONFIRMED

Assessment

Available evidence indicates public exploit-oriented templates from Greenbone and ProjectDiscovery, alongside an independent assertion that the CVE is listed by ENISA as actively exploited. This establishes meaningful public threat context, not VTP observation or applicability to any specific environment.

Why it matters

  • Public exploit-oriented tooling can lower the effort required to test or target vulnerable deployments.
  • The ENISA EU KEV assertion supports reported real-world exploitation context.
  • EPSS is high (0.85562), which is predictive context only and does not prove exploitation or exposure.

Evidence

3 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

Authoritative vulnerability metadata, affected products, severity, and technical impact are pending.

The supplied evidence does not establish exploit reliability, current campaign scope, or VTP observation.

No CISA KEV record is supplied.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Identify whether any in-scope assets use products affected by CVE-2015-7501 once authoritative metadata is available.

AI baseline history (2)
  1. BASELINE ASSESSED
    Public exploit tooling with reported active exploitationgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Limited baseline context for CVE-2015-7501gpt-5.6-sol · high
Technical severityUNKNOWNCVSS unknown · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.86100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.86; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
03

Claim provenance

Evidence and source independence

4publications detected
4underlying evidence chains

1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:OPENVAS_NASL:98b3f1f636ccacee9b2eeb5831535ddbf746813eACTIVE
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:8a15915ac64046879dfa4922f966118474d7af98ACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2015-7501ACTIVE
Evidence
04

Event history

Threat timeline

  1. 18:4205 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 18:1724 Aug
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  3. 13:0824 Aug
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2015-7501.

  4. 00:0014 Jul
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

Exploit tooling coverage changed for 49 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 49 CVEs in this pinned revision. 49 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2007-2447CVE-2011-3556CVE-2013-7448CVE-2014-2120CVE-2014-6113CVE-2014-6137CVE-2015-0930CVE-2015-3271CVE-2015-4664CVE-2015-4665CVE-2015-4666CVE-2015-4667CVE-2015-4668CVE-2015-4669CVE-2015-4852CVE-2015-6940CVE-2015-7501CVE-2016-0875CVE-2016-0876CVE-2016-0877CVE-2016-0878CVE-2016-0879CVE-2016-1289CVE-2016-1487CVE-2016-15038CVE-2016-1927CVE-2016-2038CVE-2016-2039CVE-2016-2040CVE-2016-2041CVE-2016-2230CVE-2016-2784CVE-2016-3089CVE-2016-3642CVE-2016-4350CVE-2016-5229CVE-2016-5674CVE-2016-5675CVE-2016-5676CVE-2016-5677CVE-2016-5678CVE-2016-5679CVE-2016-5680CVE-2016-6553CVE-2016-8736CVE-2025-25034CVE-2025-34110CVE-2025-34113CVE-2025-60344
Separate evidence group

Exploit tooling coverage expanded for 51 CVEs

ProjectDiscovery nuclei-templates added or materially changed exploit-oriented artifacts covering 51 CVEs. This establishes public tooling availability; it does not establish exploitation in the wild or successful execution.

CVE-2015-7501CVE-2018-11714CVE-2018-14839CVE-2018-7282CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-44228CVE-2022-1281CVE-2023-25157CVE-2023-25826CVE-2023-27350CVE-2023-31059CVE-2023-3710CVE-2023-39143CVE-2024-33605CVE-2024-57726CVE-2025-0520CVE-2025-26399CVE-2026-0558CVE-2026-11387CVE-2026-12394CVE-2026-15826CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25895CVE-2026-26217CVE-2026-32255CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-4060CVE-2026-41042CVE-2026-45695CVE-2026-49069CVE-2026-5032CVE-2026-52806CVE-2026-53753CVE-2026-54917CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-61511CVE-2026-64849CVE-2026-6854CVE-2026-69084
Separate evidence group
Original

Nuclei Templates v10.4.8 - Release Notes

New Templates Added: 112 | CVEs Added: 101 | First-time contributions: 22 🔥 Release Highlights 🔥 [CVE-2026-72898] Metabase - Unauthenticated SQL Injection (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-71362 ] Adobe Commerce/Magento - Customer Session Identity Switch (@0x_Akoko, @dinosn ) [critical] 🔥 [ CVE-2026-64849 ] MLflow Webhook SSRF - Unauth Full-Read via Redirect Bypass ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [CVE-2026-64638] WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell) ( @flx | Nick Vidovic (greenhats)) [high] 🔥 [ CVE-2026-63077 ] JetBrains TeamCity < 2026.1.3, 2025.11.7 - RCE (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-59774] Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read ( @ashish-cybersec ) [critical] 🔥 [ CVE-2026-58644 ] Microsoft SharePoint Server - WS-Federation Deserialization RCE ( @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-57219] RabbitMQ Management - OAuth 2 Client Secret Disclosure ( @Aryu-RU ) [high] 🔥 [ CVE-2026-56270 ] Flowise <= 3.0.13 - Unauth OAuth Configuration Disclosure (@0x_Akoko, @pdteam ) [high] (vKEV) 🔥 [CVE-2026-53576] Kestra <= 1.3.20 - Remote Code Execution (@0x_Akoko, @pdteam , @Aryu-RU ) [critical] (vKEV) 🔥 [ CVE-2026-52806 ] Gogs <= 0.14.2 - Auth RCE via git rebase Argument Injection ( @dhiyaneshdk , @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-49049 ] JoomShaper Helix3 <=3.1.0 - Unauth Arbitrary JSON File Write ( @dhiyaneshdk , @pdteam ) [high] (vKEV) 🔥 [ CVE-2026-48939 ] Joomla iCagenda < 3.9.10 - Unauth Arbitrary File Upload RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-40217 ] LiteLLM < 1.25.0 - Remote Code Execution ( @ritikchaddha ) [high] (vKEV) 🔥 [ CVE-2026-34908 ] UniFi OS - Authentication Bypass via Path Traversal (..%2f) ( @Boreas37 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-20896 ] Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Auth Bypass ( @prithvee07 ) [critical] (vKEV) 🔥 [ CVE-2026-19478 ] GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method Invocation (@0x_Akoko, @dhiyaneshdk ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Corrected an unclosed string literal in the CVE-2026-0558 dsl matcher (PR #16950 ). Fixed a broken matcher in the newly added CVE-2026-3395 template (PR #16886 ). Fixed the username key structure in mysql-empty-password.yaml (PR #16939 ). Fixed indentation in kubernetes-metrics.yaml (PR #16934 ). Added the missing capture group to regex extractors in oracle-containers-panel, smtp-credentials-exposure and springboot-x-application-context (PR #16663 ). Corrected the max-request counter for CVE-2021-40822 (PR #16875 ). Corrected email and password variable names in CVE-2025-68613 (PR #16918 ). Renamed Wix-detect.yaml, cve-2026-44338 .yaml and CVE-2026-44381.yaml to match the naming convention (PRs #16731 , #16729 , #16730 ). Moved 22 invalid or rejected CVE templates to vulnerabilities (PR #16889 , Issue #16115 ). Removed CVE-2024-28752 .yaml (PR #16745 ). False Negatives CVE-2017-5521 , CVE-2017-7615 and CVE-2020-23575 — regexes were placed in word matchers, so these templates could never fire (PR #16666 ). nh-c2 — corrected a dsl matcher that could never match (PR #16739 ). CVE-2026-21858 — added a /rest/sentry.js fallback to detect n8n 1.65.0 through 1.111.x (PR #16888 ). CVE-2025-14847 — now detects vulnerable MongoDB 8.0.x via buildinfo read-size truncation (PR #16741 ). CVE-2025-32969 — removed an incorrect content_type matcher that suppressed matches (PR #16704 ). CVE-2023-37629 — closed the filename quote before the .php extension so the payload is well formed (PR #16709 ). False Positives CVE-2025-29927 — added negative matchers so WAF block pages returning HTTP 200 no longer match (PR #16870 , Issue #16782 ). wp-vr-view-xss and vrview-xss — no longer fire on hosts that escape the payload (PR #16912 ). wordpress-eol — tightened an over-broad version regex (PR #16752 ). CVE-2021-24139 — both conditions must now match rather than either (PR #16748 ). Marked prec

CVE-2015-7501CVE-2017-5521CVE-2017-7615CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-24139CVE-2021-40822CVE-2022-1281CVE-2022-29013CVE-2023-25826CVE-2023-37629CVE-2024-0200CVE-2024-13985CVE-2024-28752CVE-2024-37014CVE-2024-55890CVE-2024-56064CVE-2024-57726CVE-2025-0520CVE-2025-11953CVE-2025-13342CVE-2025-13528CVE-2025-14847CVE-2025-20282CVE-2025-26399CVE-2025-29927CVE-2025-32969CVE-2025-68613CVE-2025-71324CVE-2026-0558CVE-2026-0717CVE-2026-10768CVE-2026-1115CVE-2026-11387CVE-2026-12394CVE-2026-13001CVE-2026-13147CVE-2026-14483CVE-2026-14894CVE-2026-15733CVE-2026-15826CVE-2026-16268CVE-2026-17505CVE-2026-17532CVE-2026-17594CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25231CVE-2026-25895CVE-2026-2614CVE-2026-26217CVE-2026-27542CVE-2026-27796CVE-2026-3001CVE-2026-30965CVE-2026-32255CVE-2026-3395CVE-2026-34908CVE-2026-34976CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-40280CVE-2026-4060CVE-2026-41042CVE-2026-41432CVE-2026-42461CVE-2026-44338CVE-2026-44381CVE-2026-45332CVE-2026-45695CVE-2026-48030CVE-2026-48939CVE-2026-49049CVE-2026-49069CVE-2026-50160CVE-2026-5032CVE-2026-52806CVE-2026-53519CVE-2026-53576CVE-2026-53629CVE-2026-53753CVE-2026-53755CVE-2026-53976CVE-2026-54917CVE-2026-55087CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-58138CVE-2026-58644CVE-2026-59774CVE-2026-61511CVE-2026-61808CVE-2026-63030CVE-2026-63077CVE-2026-64638CVE-2026-64849CVE-2026-65442CVE-2026-65919CVE-2026-67208CVE-2026-6826CVE-2026-6854CVE-2026-69084CVE-2026-69251CVE-2026-71209CVE-2026-71362CVE-2026-72898CVE-2026-8236CVE-2026-8237CVE-2026-8857CVE-2026-9506
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2015-7501

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2015-7501
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score58.1vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction17.11 / 20
Exploit availability7.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
Unknown · UNKNOWN
Vector
Unknown
CWE
Unknown
CPE records
0
Deterministic history records
20
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.