Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

debian логотип

CVE-2015-5622

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 all ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-3440

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2015-3440

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2015-3440

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in W ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2015-3439

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3439

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3439

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiec ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-3438

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3438

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3438

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-2213

больше 10 лет назад

SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2015-2213

больше 10 лет назад

SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2015-2213

больше 10 лет назад

SQL injection vulnerability in the wp_untrash_post_comments function i ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2014-9039

больше 11 лет назад

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9039

больше 11 лет назад

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9039

больше 11 лет назад

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x befo ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9038

больше 11 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2014-9038

больше 11 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2014-9038

больше 11 лет назад

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3. ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2014-9037

больше 11 лет назад

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2015-5622

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 all ...

CVSS2: 3.5
5%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-3440

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

CVSS2: 4.3
18%
Средний
почти 11 лет назад
nvd логотип
CVE-2015-3440

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

CVSS2: 4.3
18%
Средний
почти 11 лет назад
debian логотип
CVE-2015-3440

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in W ...

CVSS2: 4.3
18%
Средний
почти 11 лет назад
ubuntu логотип
CVE-2015-3439

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

CVSS2: 4.3
6%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-3439

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

CVSS2: 4.3
6%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-3439

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiec ...

CVSS2: 4.3
6%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-3438

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

CVSS2: 4.3
8%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-3438

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

CVSS2: 4.3
8%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-3438

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 4.3
8%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-2213

SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.

CVSS2: 7.5
11%
Средний
больше 10 лет назад
nvd логотип
CVE-2015-2213

SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.

CVSS2: 7.5
11%
Средний
больше 10 лет назад
debian логотип
CVE-2015-2213

SQL injection vulnerability in the wp_untrash_post_comments function i ...

CVSS2: 7.5
11%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2014-9039

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-9039

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-9039

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x befo ...

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

CVSS2: 6.4
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3. ...

CVSS2: 6.4
4%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9037

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

CVSS2: 6.8
3%
Низкий
больше 11 лет назад

Уязвимостей на страницу