CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73529  CVE-2014-6230  Candidate  WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header.  Assigned (20140904)  None (candidate not yet proposed)    View
22120  CVE-2006-6016  Candidate  wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.  Assigned (20061121)  None (candidate not yet proposed)    View
36884  CVE-2008-6767  Candidate  wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.  Assigned (20090428)  None (candidate not yet proposed)    View
53182  CVE-2011-5270  Candidate  wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.  Assigned (20140120)  None (candidate not yet proposed)    View
57665  CVE-2012-4422  Candidate  wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.  Assigned (20120821)  None (candidate not yet proposed)    View

Page 137 of 20943, showing 5 records out of 104715 total, starting on record 681, ending on 685

Actions