CVE-2020-12062high · CVSS 7.5 — The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a maliciou
CVE-2020-14145medium · CVSS 5.9 — The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This a
CVE-2020-15778high · CVSS 7.4 — scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destinat
CVE-2023-38408critical · CVSS 9.8 — The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
CVE-2025-26465medium · CVSS 6.8 — A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malic
CVE-2019-8942high · CVSS 8.8 — WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an a
CVE-2019-16780medium · CVSS 5.8 — WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is
CVE-2020-11026high · CVSS 8.7 — In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon
CVE-2020-11027medium · CVSS 6.1 — In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be
CVE-2020-11029medium · CVSS 5.8 — In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site
CVE-2022-3590medium · CVSS 5.9 — WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation ch
CVE-2023-2745medium · CVSS 5.4 — WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthen