CVE-2023-38408critical · CVSS 9.8 — The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
CVE-2024-6387high · CVSS 8.1 — A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle som
CVE-2025-26465medium · CVSS 6.8 — A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malic
CVE-2019-6977high · CVSS 8.8 — gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.
CVE-2019-11044low · CVSS 3.7 — In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and
CVE-2019-11045low · CVSS 3.7 — In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and tr
CVE-2019-11046low · CVSS 3.7 — In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be
CVE-2019-11047medium · CVSS 4.8 — When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7
CVE-2019-11050medium · CVSS 4.8 — When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7
CVE-2009-2853critical · CVSS 10.0 — Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php,
CVE-2011-4898medium · CVSS 5.0 — wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacki
CVE-2011-4899high · CVSS 7.5 — wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database ser
CVE-2012-0782medium · CVSS 4.3 — Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlie
CVE-2012-0937medium · CVSS 5.0 — wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to ex
CVE-2012-2399critical · CVSS 10.0 — Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image
CVE-2012-2400critical · CVSS 10.0 — Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
CVE-2012-2401medium · CVSS 5.0 — Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the
CVE-2012-2402medium · CVSS 5.5 — wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and de
CVE-2012-2403medium · CVSS 4.3 — wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote
CVE-2012-2404medium · CVSS 4.3 — wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site
CVE-2012-1936medium · CVSS 6.8 — The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a
CVE-2011-4956medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspec
CVE-2011-4957medium · CVSS 5.0 — The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the
CVE-2012-3384medium · CVSS 6.8 — Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentica
CVE-2012-3385medium · CVSS 5.0 — WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or con
CVE-2010-5106medium · CVSS 6.5 — The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote au
CVE-2012-4421medium · CVSS 4.0 — The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows
CVE-2012-4422low · CVSS 3.5 — wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges b
CVE-2013-0235medium · CVSS 6.4 — The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attack
CVE-2013-0236medium · CVSS 4.3 — Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML
CVE-2013-0237medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other prod
CVE-2013-2199medium · CVSS 4.3 — The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to
CVE-2013-2200medium · CVSS 4.0 — WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restric
CVE-2013-2201medium · CVSS 4.3 — Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML
CVE-2013-2202medium · CVSS 4.3 — WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity dec
CVE-2013-2203medium · CVSS 4.3 — WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an inva
CVE-2013-2204medium · CVSS 4.3 — moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider
CVE-2013-2205medium · CVSS 4.3 — The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote atta
CVE-2012-3414medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image
CVE-2010-5293medium · CVSS 5.8 — wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote
CVE-2010-5294medium · CVSS 4.3 — Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPres
CVE-2010-5295medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary
CVE-2010-5296medium · CVSS 4.9 — wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for th
CVE-2010-5297low · CVSS 2.1 — WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once chang
CVE-2011-5270medium · CVSS 4.0 — wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticat
CVE-2012-6633medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbi
CVE-2012-6634medium · CVSS 6.4 — wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachm
CVE-2012-6635medium · CVSS 4.0 — wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remot
CVE-2014-0165medium · CVSS 4.0 — WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related
CVE-2014-0166medium · CVSS 6.4 — The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determi