NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25599 | CVE-2015-4065 | Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php. | 2 | 3.5 | Low | 2017-01-19 | 2015-05-28 | View | |
| 25598 | CVE-2015-4064 | SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php. | 2 | 6.5 | Medium | 2017-01-19 | 2015-05-28 | View | |
| 25597 | CVE-2015-4063 | Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php. | 2 | 3.5 | Low | 2017-01-19 | 2015-05-28 | View | |
| 25596 | CVE-2015-4062 | SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php. | 2 | 6.5 | Medium | 2017-01-19 | 2015-05-28 | View | |
| 25595 | CVE-2015-4060 | Heap-based buffer overflow in the TermProxy (WLTermProxyService.exe) service in Wavelink ConnectPro allows remote attackers to execute arbitrary code via a large HTTP header. | 2 | 10 | High | 2017-01-19 | 2016-12-05 | View |
Page 3240 of 17672, showing 5 records out of 88360 total, starting on record 16196, ending on 16200