Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.8
CVE-2015-5731
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication o…
WordPress
after 4.2.3
MEDIUM 5.0
CVE-2015-5730EPSS 7%
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison…
WordPress
after 4.2.3
HIGH 7.5
CVE-2015-2213EPSS 9%
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to exe…
WordPress
after 4.2.3
MEDIUM 6.4
CVE-2014-9038
wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct serve…
WordPress
after 3.7.4
MEDIUM 6.8
CVE-2014-9037
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle…
WordPress
after 3.7.4
MEDIUM 5.0
CVE-2014-9034EPSS 83%
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause…
WordPress
after 3.7.4
MEDIUM 6.8
CVE-2014-9033
Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authe…
WordPress
Patch available
HIGH 7.5
CVE-2003-1599
PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL i…
WordPress
No fix yet
HIGH 7.5
CVE-2003-1598
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts va…
WordPress
after 0.7
MEDIUM 5.0
CVE-2014-5265
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations with…
WordPress
after 3.9.1
MEDIUM 5.0
CVE-2014-5266EPSS 24%
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of ele…
WordPress
after 3.9.1
HIGH 7.5
CVE-2014-5203
wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbit…
WordPress
Patch available
MEDIUM 6.8
CVE-2014-5205
wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, whic…
WordPress
after 3.9.1
MEDIUM 6.4
CVE-2014-0166EPSS 9%
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the va…
WordPress
after 3.7.1
MEDIUM 6.4
CVE-2012-6634
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restr…
WordPress
after 3.3.2
MEDIUM 5.8
CVE-2010-5293
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers…
WordPress
after 3.0.1
MEDIUM 5.0
CVE-2013-7240EPSS 20%
Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary f…
WordPress
No fix yet
MEDIUM 6.8
CVE-2013-7233
Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows …
WordPress
after 2.0.11
HIGH 7.5
CVE-2013-4339EPSS 7%
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection r…
WordPress
after 3.6
HIGH 7.5
CVE-2013-4338EPSS 9%
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to ex…
WordPress
after 3.6
MEDIUM 6.4
CVE-2013-0235EPSS 29%
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by spe…
WordPress
after 3.5.0
MEDIUM 6.8
CVE-2013-3250
Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the au…
Wp Maintenance Mode Plugin
after 1.8.7
HIGH 7.5
CVE-2011-5216
SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary S…
WordPress
after 1.0.6.6
MEDIUM 6.0
CVE-2012-5350
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execu…
Pay With Tweet
after 1.1
MEDIUM 6.8
CVE-2012-4448
Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of admi…
WordPress
No fix yet
MEDIUM 6.5
CVE-2010-5106
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticat…
WordPress
after 3.0.2
MEDIUM 6.8
CVE-2012-3384
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of u…
WordPress
after 3.4.0
MEDIUM 5.0
CVE-2012-3385
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors…
WordPress
after 3.4.0
MEDIUM 5.0
CVE-2011-4957
The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE libr…
WordPress
after 3.1
MEDIUM 5.0
CVE-2012-3588EPSS 11%
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files vi…
Plugin Newsletter Plugin
No fix yet