NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16502  CVE-2010-5293  wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.    5.8  Medium  2017-01-18  2014-01-21  View
32952  CVE-2014-5203  wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.    7.5  High  2017-01-19  2014-08-28  View
35855  CVE-2014-9034  wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.    Medium  2017-01-19  2016-04-04  View
38269  CVE-2013-2173  wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.    4.3  Medium  2017-01-18  2013-08-22  View
16505  CVE-2010-5296  wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.    4.9  Medium  2017-01-18  2014-01-21  View

Page 155 of 17672, showing 5 records out of 88360 total, starting on record 771, ending on 775

Actions