CVE-2023-28531critical · CVSS 9.8 — ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected v
CVE-2023-38408critical · CVSS 9.8 — The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
CVE-2023-48795medium · CVSS 5.9 — The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
CVE-2023-51384medium · CVSS 5.5 — In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified
CVE-2023-51385medium · CVSS 6.5 — In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is refere
CVE-2023-51767high · CVSS 7.0 — OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer val
CVE-2024-6387high · CVSS 8.1 — A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle som
CVE-2025-26465medium · CVSS 6.8 — A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malic
CVE-2025-32728medium · CVSS 4.3 — In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent
CVE-2026-35385high · CVSS 7.5 — In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the
CVE-2026-35387low · CVSS 3.1 — OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgo
CVE-2026-35388low · CVSS 2.5 — OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-35414medium · CVSS 4.2 — OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a
CVE-2026-59995medium · CVSS 4.2 — sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker
CVE-2026-59996medium · CVSS 4.2 — scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destina
CVE-2026-59997medium · CVSS 4.2 — internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-l
CVE-2026-59998medium · CVSS 4.8 — sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windo
CVE-2026-59999medium · CVSS 5.9 — In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVE-2026-60000low · CVSS 3.7 — sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempt
CVE-2026-60001medium · CVSS 6.5 — sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-60002high · CVSS 7.7 — ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only
CVE-2011-4969medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj
CVE-2019-11358medium · CVSS 6.1 — jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
CVE-2020-7656medium · CVSS 6.1 — jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML
CVE-2021-39200medium · CVSS 5.3 — WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versio
CVE-2021-39202high · CVSS 7.6 — WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versio
CVE-2021-39203medium · CVSS 6.8 — WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versio
CVE-2022-21661high · CVSS 8.0 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitizatio
CVE-2022-21662high · CVSS 8.0 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticate
CVE-2022-21663medium · CVSS 6.6 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with
CVE-2022-21664high · CVSS 7.4 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanit
CVE-2022-43497medium · CVSS 6.1 — Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary scri
CVE-2022-43500medium · CVSS 6.1 — Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary scri
CVE-2022-43504medium · CVSS 5.3 — Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email addr
CVE-2022-3590medium · CVSS 5.9 — WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation ch
CVE-2023-22622medium · CVSS 5.3 — WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the so
CVE-2023-2745medium · CVSS 5.4 — WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthen
CVE-2023-39999medium · CVSS 4.3 — Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1
CVE-2023-5561medium · CVSS 5.3 — WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the em
CVE-2024-31210high · CVSS 7.6 — WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plug
CVE-2022-4973medium · CVSS 4.9 — WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with acce