Количество 1 912
Количество 1 912
CVE-2020-28037
is_blog_installed in wp-includes/functions.php in WordPress before 5.5 ...
CVE-2020-28036
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
CVE-2020-28036
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
CVE-2020-28036
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allow ...
CVE-2020-28035
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
CVE-2020-28035
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
CVE-2020-28035
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC ...
CVE-2020-28034
WordPress before 5.5.2 allows XSS associated with global variables.
CVE-2020-28034
WordPress before 5.5.2 allows XSS associated with global variables.
CVE-2020-28034
WordPress before 5.5.2 allows XSS associated with global variables.
CVE-2020-28033
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
CVE-2020-28033
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
CVE-2020-28033
WordPress before 5.5.2 mishandles embeds from disabled sites on a mult ...
CVE-2020-28032
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
CVE-2020-28032
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
CVE-2020-28032
WordPress before 5.5.2 mishandles deserialization requests in wp-inclu ...
CVE-2020-25286
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
CVE-2020-25286
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
CVE-2020-25286
In wp-includes/comment-template.php in WordPress before 5.4.2, comment ...
CVE-2020-11030
In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-28037 is_blog_installed in wp-includes/functions.php in WordPress before 5.5 ... | CVSS3: 9.8 | 8% Низкий | больше 5 лет назад | |
CVE-2020-28036 wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post. | CVSS3: 9.8 | 5% Низкий | больше 5 лет назад | |
CVE-2020-28036 wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post. | CVSS3: 9.8 | 5% Низкий | больше 5 лет назад | |
CVE-2020-28036 wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allow ... | CVSS3: 9.8 | 5% Низкий | больше 5 лет назад | |
CVE-2020-28035 WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. | CVSS3: 9.8 | 4% Низкий | больше 5 лет назад | |
CVE-2020-28035 WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. | CVSS3: 9.8 | 4% Низкий | больше 5 лет назад | |
CVE-2020-28035 WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC ... | CVSS3: 9.8 | 4% Низкий | больше 5 лет назад | |
CVE-2020-28034 WordPress before 5.5.2 allows XSS associated with global variables. | CVSS3: 6.1 | 2% Низкий | больше 5 лет назад | |
CVE-2020-28034 WordPress before 5.5.2 allows XSS associated with global variables. | CVSS3: 6.1 | 2% Низкий | больше 5 лет назад | |
CVE-2020-28034 WordPress before 5.5.2 allows XSS associated with global variables. | CVSS3: 6.1 | 2% Низкий | больше 5 лет назад | |
CVE-2020-28033 WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed. | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад | |
CVE-2020-28033 WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed. | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад | |
CVE-2020-28033 WordPress before 5.5.2 mishandles embeds from disabled sites on a mult ... | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад | |
CVE-2020-28032 WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. | CVSS3: 9.8 | 16% Средний | больше 5 лет назад | |
CVE-2020-28032 WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. | CVSS3: 9.8 | 16% Средний | больше 5 лет назад | |
CVE-2020-28032 WordPress before 5.5.2 mishandles deserialization requests in wp-inclu ... | CVSS3: 9.8 | 16% Средний | больше 5 лет назад | |
CVE-2020-25286 In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public. | CVSS3: 5.3 | 2% Низкий | почти 6 лет назад | |
CVE-2020-25286 In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public. | CVSS3: 5.3 | 2% Низкий | почти 6 лет назад | |
CVE-2020-25286 In wp-includes/comment-template.php in WordPress before 5.4.2, comment ... | CVSS3: 5.3 | 2% Низкий | почти 6 лет назад | |
CVE-2020-11030 In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33). | CVSS3: 6.4 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу