Show filters
472 Total Results
Displaying 81-90 of 472
Sort by:
Attacker Value
Unknown

CVE-2021-29476

Disclosure Date: April 27, 2021 (last updated February 22, 2025)
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
Attacker Value
Unknown

CVE-2021-29450

Disclosure Date: April 15, 2021 (last updated February 22, 2025)
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to receive the fix.
Attacker Value
Unknown

CVE-2021-29447

Disclosure Date: April 15, 2021 (last updated February 22, 2025)
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.
Attacker Value
Unknown

CVE-2020-28036

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
Attacker Value
Unknown

CVE-2020-28039

Disclosure Date: November 02, 2020 (last updated November 08, 2023)
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
Attacker Value
Unknown

CVE-2020-28040

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
Attacker Value
Unknown

CVE-2020-28035

Disclosure Date: November 02, 2020 (last updated November 08, 2023)
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
Attacker Value
Unknown

CVE-2020-28034

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
WordPress before 5.5.2 allows XSS associated with global variables.
Attacker Value
Unknown

CVE-2020-28032

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
Attacker Value
Unknown

CVE-2020-28033

Disclosure Date: November 02, 2020 (last updated November 08, 2023)
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.