CVE-2023-38408critical · CVSS 9.8 — The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
CVE-2024-6387high · CVSS 8.1 — A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle som
CVE-2025-26465medium · CVSS 6.8 — A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malic
CVE-2011-4969medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj
CVE-2019-8942high · CVSS 8.8 — WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an a
CVE-2019-16780medium · CVSS 5.8 — WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is
CVE-2020-11026high · CVSS 8.7 — In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon
CVE-2020-11027medium · CVSS 6.1 — In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be
CVE-2020-11029medium · CVSS 5.8 — In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site
CVE-2022-3590medium · CVSS 5.9 — WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation ch
CVE-2023-2745medium · CVSS 5.4 — WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthen