NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
51316  CVE-2009-4170  WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.    Medium  2017-01-07  2009-12-03  View
44215  CVE-2012-2404  wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.    4.3  Medium  2017-01-19  2012-06-28  View
33783  CVE-2014-6230  WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header.    4.3  Medium  2017-01-19  2014-10-27  View
64577  CVE-2006-6016  wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.    Medium  2016-12-20  2008-09-05  View
6498  CVE-2008-6767  wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.    10  High  2017-01-03  2009-08-26  View

Page 156 of 17672, showing 5 records out of 88360 total, starting on record 776, ending on 780

Actions