Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

debian логотип

CVE-2016-5836

около 10 лет назад

The oEmbed protocol implementation in WordPress before 4.5.3 allows re ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-5835

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5835

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5835

около 10 лет назад

WordPress before 4.5.3 allows remote attackers to obtain sensitive rev ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-5834

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5834

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5834

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-5833

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5833

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5833

около 10 лет назад

Cross-site scripting (XSS) vulnerability in the column_title function ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-5832

около 10 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5832

около 10 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5832

около 10 лет назад

The customizer in WordPress before 4.5.3 allows remote attackers to by ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-4029

почти 10 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2016-4029

почти 10 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2016-4029

почти 10 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP addres ...

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2016-2222

около 10 лет назад

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2016-2222

около 10 лет назад

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2016-2222

около 10 лет назад

The wp_http_validate_url function in wp-includes/http.php in WordPress ...

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2016-2221

около 10 лет назад

Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2016-5836

The oEmbed protocol implementation in WordPress before 4.5.3 allows re ...

CVSS3: 7.5
4%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
4%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

CVSS3: 7.5
4%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive rev ...

CVSS3: 7.5
4%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-5834

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
2%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5834

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

CVSS3: 6.1
2%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5834

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link ...

CVSS3: 6.1
2%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-5833

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
2%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5833

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

CVSS3: 6.1
2%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5833

Cross-site scripting (XSS) vulnerability in the column_title function ...

CVSS3: 6.1
2%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-5832

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5832

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

CVSS3: 7.5
3%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5832

The customizer in WordPress before 4.5.3 allows remote attackers to by ...

CVSS3: 7.5
3%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
4%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
4%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-4029

WordPress before 4.5 does not consider octal and hexadecimal IP addres ...

CVSS3: 8.6
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-2222

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

CVSS3: 8.6
9%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-2222

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

CVSS3: 8.6
9%
Низкий
около 10 лет назад
debian логотип
CVE-2016-2222

The wp_http_validate_url function in wp-includes/http.php in WordPress ...

CVSS3: 8.6
9%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-2221

Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.

CVSS3: 7.4
5%
Низкий
около 10 лет назад

Уязвимостей на страницу