CVE-2020-36326
- EPSS 1.03%
- Veröffentlicht 28.04.2021 03:15:07
- Zuletzt bearbeitet 21.11.2024 05:29:17
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were alway...
CVE-2021-29450
- EPSS 2.08%
- Veröffentlicht 15.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:07
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with ...
CVE-2021-29447
- EPSS 90.58%
- Veröffentlicht 15.04.2021 21:15:17
- Zuletzt bearbeitet 21.11.2024 06:01:07
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files i...
CVE-2020-28038
- EPSS 16.02%
- Veröffentlicht 02.11.2020 21:15:31
- Zuletzt bearbeitet 21.11.2024 05:22:15
WordPress before 5.5.2 allows stored XSS via post slugs.
CVE-2020-28039
- EPSS 6%
- Veröffentlicht 02.11.2020 21:15:31
- Zuletzt bearbeitet 21.11.2024 05:22:15
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
CVE-2020-28040
- EPSS 0.31%
- Veröffentlicht 02.11.2020 21:15:31
- Zuletzt bearbeitet 21.11.2024 05:22:15
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
CVE-2020-28032
- EPSS 20.72%
- Veröffentlicht 02.11.2020 21:15:30
- Zuletzt bearbeitet 21.11.2024 05:22:14
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
CVE-2020-28033
- EPSS 1.26%
- Veröffentlicht 02.11.2020 21:15:30
- Zuletzt bearbeitet 21.11.2024 05:22:14
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
CVE-2020-28034
- EPSS 2.68%
- Veröffentlicht 02.11.2020 21:15:30
- Zuletzt bearbeitet 21.11.2024 05:22:14
WordPress before 5.5.2 allows XSS associated with global variables.
CVE-2020-28035
- EPSS 4.88%
- Veröffentlicht 02.11.2020 21:15:30
- Zuletzt bearbeitet 21.11.2024 05:22:14
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.