NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20970 | CVE-2016-5837 | WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
19749 | CVE-2016-4029 | WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address. | 2 | 5 | Medium | 2017-07-18 | 2017-07-17 | View | |
26730 | CVE-2015-5623 | WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php. | 2 | 4 | Medium | 2017-07-18 | 2017-07-17 | View | |
35858 | CVE-2014-9037 | WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash. | 2 | 6.8 | Medium | 2017-01-19 | 2016-06-30 | View | |
29083 | CVE-2014-0165 | WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php. | 2 | 4 | Medium | 2017-01-19 | 2014-04-10 | View |
Page 164 of 17672, showing 5 records out of 88360 total, starting on record 816, ending on 820