NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
20970  CVE-2016-5837  WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.    Medium  2017-01-19  2016-11-29  View
19749  CVE-2016-4029  WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.    Medium  2017-07-18  2017-07-17  View
26730  CVE-2015-5623  WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.    Medium  2017-07-18  2017-07-17  View
35858  CVE-2014-9037  WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.    6.8  Medium  2017-01-19  2016-06-30  View
29083  CVE-2014-0165  WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.    Medium  2017-01-19  2014-04-10  View

Page 164 of 17672, showing 5 records out of 88360 total, starting on record 816, ending on 820

Actions