NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
51316 | CVE-2009-4170 | WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-07 | 2009-12-03 | View | |
44215 | CVE-2012-2404 | wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2012-06-28 | View | |
33783 | CVE-2014-6230 | WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header. | 2 | 4.3 | Medium | 2017-01-19 | 2014-10-27 | View | |
64577 | CVE-2006-6016 | wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter. | 2 | 4 | Medium | 2016-12-20 | 2008-09-05 | View | |
6498 | CVE-2008-6767 | wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request. | 2 | 10 | High | 2017-01-03 | 2009-08-26 | View |
Page 156 of 17672, showing 5 records out of 88360 total, starting on record 776, ending on 780