Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2021-29476
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests…
Requests
Patch available
MEDIUM 6.5
CVE-2021-29447EPSS 86%
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leadi…
WordPress
5.7.1+
CRITICAL 9.1
CVE-2020-28039
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a m…
WordPress
5.5.2+
MEDIUM 6.1
CVE-2020-28038
WordPress before 5.5.2 allows stored XSS via post slugs.
WordPress
5.5.2+
CRITICAL 9.8
CVE-2020-28032EPSS 16%
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
WordPress
5.5.2+
CRITICAL 9.8
CVE-2020-28035
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
WordPress
5.5.2+
CRITICAL 9.8
CVE-2020-28036EPSS 5%
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
WordPress
5.5.2+
CRITICAL 9.8
CVE-2020-28037EPSS 8%
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might al…
WordPress
5.5.2+
HIGH 7.5
CVE-2020-28033
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
WordPress
5.5.2+
MEDIUM 6.1
CVE-2020-28034
WordPress before 5.5.2 allows XSS associated with global variables.
WordPress
5.5.2+
MEDIUM 5.3
CVE-2020-25286
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if th…
WordPress
5.4.2+
MEDIUM 6.8
CVE-2020-4047
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file atta…
WordPress
3.7.34 / 3.8.34+
MEDIUM 5.7
CVE-2020-4048
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading …
WordPress
3.7.34 / 3.8.34+
MEDIUM 5.4
CVE-2020-4046
In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfil…
WordPress
3.7.34 / 3.8.34+
HIGH 7.5
CVE-2020-11028
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of…
WordPress
5.4.1+
MEDIUM 5.4
CVE-2020-11026
In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing…
WordPress
3.7.33 / 3.8.33+
MEDIUM 5.4
CVE-2020-11030
In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block ed…
WordPress
5.4.1+
MEDIUM 5.4
CVE-2020-11025
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be ex…
WordPress
5.4.1+
CRITICAL 9.8
CVE-2019-20041
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sa…
WordPress
5.3.1+
MEDIUM 6.1
CVE-2019-20042
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cr…
WordPress
5.3.1+
MEDIUM 5.4
CVE-2019-16780
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed …
WordPress
5.3.1+
MEDIUM 5.4
CVE-2019-16781
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is exe…
WordPress
5.3.1+
HIGH 8.8
CVE-2019-17675
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
WordPress
5.2.4+
HIGH 7.5
CVE-2019-17673
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
WordPress
5.2.4+
MEDIUM 6.1
CVE-2019-17672
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
WordPress
5.2.4+
MEDIUM 5.4
CVE-2019-17674
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
WordPress
5.2.4+
CRITICAL 9.8
CVE-2019-17669EPSS 5%
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name a…
WordPress
5.2.4+
CRITICAL 9.8
CVE-2019-17670
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relat…
WordPress
5.2.4+
MEDIUM 5.3
CVE-2019-17671EPSS 37%
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
WordPress
5.2.4+
MEDIUM 6.1
CVE-2019-16221
WordPress before 5.2.3 allows reflected XSS in the dashboard.
WordPress
5.2.3+