NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26803  CVE-2015-5731  Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.    6.8  Medium  2017-01-19  2016-12-07  View
26804  CVE-2015-5732  Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.    4.3  Medium  2017-01-19  2016-12-07  View
26805  CVE-2015-5733  Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.    4.3  Medium  2017-01-19  2016-12-07  View
26806  CVE-2015-5734  Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.    4.3  Medium  2017-01-19  2016-12-07  View
26807  CVE-2015-5735  The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to write to arbitrary memory locations via a 0x226108 ioctl call.    7.2  High  2017-01-19  2016-12-21  View

Page 14681 of 17672, showing 5 records out of 88360 total, starting on record 73401, ending on 73405

Actions