Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

nvd логотип

CVE-2014-9039

больше 10 лет назад

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9039

больше 10 лет назад

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x befo ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9038

больше 10 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2014-9038

больше 10 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2014-9038

больше 10 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3. ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2014-9037

больше 10 лет назад

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-9037

больше 10 лет назад

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-9037

больше 10 лет назад

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4. ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9036

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9036

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9036

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3. ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9035

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9035

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9035

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in Press This in WordPress be ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9034

больше 10 лет назад

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS2: 5
EPSS: Высокий
nvd логотип

CVE-2014-9034

больше 10 лет назад

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS2: 5
EPSS: Высокий
debian логотип

CVE-2014-9034

больше 10 лет назад

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3 ...

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2014-9033

больше 10 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-9033

больше 10 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-9033

больше 10 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-login.php in Wor ...

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-9039

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9039

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x befo ...

CVSS2: 4.3
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3. ...

CVSS2: 6.4
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-9037

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS2: 6.8
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9037

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS2: 6.8
3%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9037

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4. ...

CVSS2: 6.8
3%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-9036

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9036

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9036

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3. ...

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-9035

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9035

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9035

Cross-site scripting (XSS) vulnerability in Press This in WordPress be ...

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-9034

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS2: 5
72%
Высокий
больше 10 лет назад
nvd логотип
CVE-2014-9034

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

CVSS2: 5
72%
Высокий
больше 10 лет назад
debian логотип
CVE-2014-9034

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3 ...

CVSS2: 5
72%
Высокий
больше 10 лет назад
ubuntu логотип
CVE-2014-9033

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9033

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9033

Cross-site request forgery (CSRF) vulnerability in wp-login.php in Wor ...

CVSS2: 6.8
1%
Низкий
больше 10 лет назад

Уязвимостей на страницу