Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

debian логотип

CVE-2017-6816

больше 9 лет назад

In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2017-6815

больше 9 лет назад

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-6815

больше 9 лет назад

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-6815

больше 9 лет назад

In WordPress before 4.7.3 (wp-includes/pluggable.php), control charact ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-6814

больше 9 лет назад

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-6814

больше 9 лет назад

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-6814

больше 9 лет назад

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-6514

около 7 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-6514

около 7 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-6514

около 7 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remo ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-5612

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5612

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5612

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-5610

больше 9 лет назад

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-5610

больше 9 лет назад

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-5610

больше 9 лет назад

wp-admin/includes/class-wp-press-this.php in Press This in WordPress b ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-5493

больше 9 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-5493

больше 9 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-5493

больше 9 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPre ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-5492

больше 9 лет назад

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2017-6816

In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can ...

CVSS3: 4.9
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-6815

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

CVSS3: 6.1
3%
Низкий
больше 9 лет назад
nvd логотип
CVE-2017-6815

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

CVSS3: 6.1
3%
Низкий
больше 9 лет назад
debian логотип
CVE-2017-6815

In WordPress before 4.7.3 (wp-includes/pluggable.php), control charact ...

CVSS3: 6.1
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-6814

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.

CVSS3: 5.4
3%
Низкий
больше 9 лет назад
nvd логотип
CVE-2017-6814

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.

CVSS3: 5.4
3%
Низкий
больше 9 лет назад
debian логотип
CVE-2017-6814

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting ...

CVSS3: 5.4
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-6514

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
3%
Низкий
около 7 лет назад
nvd логотип
CVE-2017-6514

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
3%
Низкий
около 7 лет назад
debian логотип
CVE-2017-6514

WordPress 4.7.2 mishandles listings of post authors, which allows remo ...

CVSS3: 5.3
3%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2017-5612

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS3: 6.1
3%
Низкий
больше 9 лет назад
nvd логотип
CVE-2017-5612

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVSS3: 6.1
3%
Низкий
больше 9 лет назад
debian логотип
CVE-2017-5612

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp ...

CVSS3: 6.1
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-5610

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS3: 5.3
5%
Низкий
больше 9 лет назад
nvd логотип
CVE-2017-5610

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

CVSS3: 5.3
5%
Низкий
больше 9 лет назад
debian логотип
CVE-2017-5610

wp-admin/includes/class-wp-press-this.php in Press This in WordPress b ...

CVSS3: 5.3
5%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
3%
Низкий
больше 9 лет назад
nvd логотип
CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
3%
Низкий
больше 9 лет назад
debian логотип
CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPre ...

CVSS3: 7.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-5492

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.

CVSS3: 8.8
2%
Низкий
больше 9 лет назад

Уязвимостей на страницу