Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Requests CRITICAL 9.8
CVE-2021-29476

Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests…

Patch available
Fix from $2,300 2021-04-27
WordPress MEDIUM 6.5
CVE-2021-29447EPSS 86%

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leadi…

Fix: 5.7.1+
Fix from $1,600 2021-04-15
WordPress CRITICAL 9.1
CVE-2020-28039

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a m…

Fix: 5.5.2+
Fix from $2,300 2020-11-02
WordPress MEDIUM 6.1
CVE-2020-28038

WordPress before 5.5.2 allows stored XSS via post slugs.

Fix: 5.5.2+
Fix from $1,600 2020-11-02
WordPress CRITICAL 9.8
CVE-2020-28032EPSS 16%

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

Fix: 5.5.2+
Fix from $2,300 2020-11-02
WordPress CRITICAL 9.8
CVE-2020-28035

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

Fix: 5.5.2+
Fix from $2,300 2020-11-02
WordPress CRITICAL 9.8
CVE-2020-28036EPSS 5%

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

Fix: 5.5.2+
Fix from $2,300 2020-11-02
WordPress CRITICAL 9.8
CVE-2020-28037EPSS 8%

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might al…

Fix: 5.5.2+
Fix from $2,300 2020-11-02
WordPress HIGH 7.5
CVE-2020-28033

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

Fix: 5.5.2+
Fix from $1,950 2020-11-02
WordPress MEDIUM 6.1
CVE-2020-28034

WordPress before 5.5.2 allows XSS associated with global variables.

Fix: 5.5.2+
Fix from $1,600 2020-11-02
WordPress MEDIUM 5.3
CVE-2020-25286

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if th…

Fix: 5.4.2+
Fix from $1,600 2020-09-13
WordPress MEDIUM 6.8
CVE-2020-4047

In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file atta…

Fix: 3.7.34 / 3.8.34+
Fix from $1,600 2020-06-12
WordPress MEDIUM 5.7
CVE-2020-4048

In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading …

Fix: 3.7.34 / 3.8.34+
Fix from $1,600 2020-06-12
WordPress MEDIUM 5.4
CVE-2020-4046

In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfil…

Fix: 3.7.34 / 3.8.34+
Fix from $1,600 2020-06-12
WordPress HIGH 7.5
CVE-2020-11028

In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of…

Fix: 5.4.1+
Fix from $1,950 2020-04-30
WordPress MEDIUM 5.4
CVE-2020-11026

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing…

Fix: 3.7.33 / 3.8.33+
Fix from $1,600 2020-04-30
WordPress MEDIUM 5.4
CVE-2020-11030

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block ed…

Fix: 5.4.1+
Fix from $1,600 2020-04-30
WordPress MEDIUM 5.4
CVE-2020-11025

In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be ex…

Fix: 5.4.1+
Fix from $1,600 2020-04-30
WordPress CRITICAL 9.8
CVE-2019-20041

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sa…

Fix: 5.3.1+
Fix from $2,300 2019-12-27
WordPress MEDIUM 6.1
CVE-2019-20042

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cr…

Fix: 5.3.1+
Fix from $1,600 2019-12-27
WordPress MEDIUM 5.4
CVE-2019-16780

WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed …

Fix: 5.3.1+
Fix from $1,600 2019-12-26
WordPress MEDIUM 5.4
CVE-2019-16781

In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is exe…

Fix: 5.3.1+
Fix from $1,600 2019-12-26
WordPress HIGH 8.8
CVE-2019-17675

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

Fix: 5.2.4+
Fix from $1,950 2019-10-17
WordPress HIGH 7.5
CVE-2019-17673

WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

Fix: 5.2.4+
Fix from $1,950 2019-10-17
WordPress MEDIUM 6.1
CVE-2019-17672

WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

Fix: 5.2.4+
Fix from $1,600 2019-10-17
WordPress MEDIUM 5.4
CVE-2019-17674

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

Fix: 5.2.4+
Fix from $1,600 2019-10-17
WordPress CRITICAL 9.8
CVE-2019-17669EPSS 5%

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name a…

Fix: 5.2.4+
Fix from $2,300 2019-10-17
WordPress CRITICAL 9.8
CVE-2019-17670

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relat…

Fix: 5.2.4+
Fix from $2,300 2019-10-17
WordPress MEDIUM 5.3
CVE-2019-17671EPSS 37%

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

Fix: 5.2.4+
Fix from $1,600 2019-10-17
WordPress MEDIUM 6.1
CVE-2019-16221

WordPress before 5.2.3 allows reflected XSS in the dashboard.

Fix: 5.2.3+
Fix from $1,600 2019-09-11