NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
16502 | CVE-2010-5293 | wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match. | 2 | 5.8 | Medium | 2017-01-18 | 2014-01-21 | View | |
32952 | CVE-2014-5203 | wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data. | 2 | 7.5 | High | 2017-01-19 | 2014-08-28 | View | |
35855 | CVE-2014-9034 | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016. | 2 | 5 | Medium | 2017-01-19 | 2016-04-04 | View | |
38269 | CVE-2013-2173 | wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie. | 2 | 4.3 | Medium | 2017-01-18 | 2013-08-22 | View | |
16505 | CVE-2010-5296 | wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. | 2 | 4.9 | Medium | 2017-01-18 | 2014-01-21 | View |
Page 155 of 17672, showing 5 records out of 88360 total, starting on record 771, ending on 775