NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
7129 | CVE-2017-5491 | wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
35860 | CVE-2014-9039 | wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message. | 2 | 4.3 | Medium | 2017-01-19 | 2016-06-30 | View | |
53783 | CVE-2007-1599 | wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter. | 2 | 6.5 | Medium | 2017-01-07 | 2008-09-05 | View | |
49988 | CVE-2009-2762 | wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array. | 2 | 7.5 | High | 2017-01-07 | 2009-08-15 | View | |
52341 | CVE-2007-0109 | wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View |
Page 152 of 17672, showing 5 records out of 88360 total, starting on record 756, ending on 760