CVE-2019-17673
- EPSS 5.46%
- Published 17.10.2019 13:15:11
- Last modified 21.11.2024 04:32:45
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
CVE-2019-17674
- EPSS 3.34%
- Published 17.10.2019 13:15:11
- Last modified 21.11.2024 04:32:45
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
CVE-2019-17675
- EPSS 4.65%
- Published 17.10.2019 13:15:11
- Last modified 21.11.2024 04:32:45
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVE-2019-17669
- EPSS 12.19%
- Published 17.10.2019 13:15:10
- Last modified 21.11.2024 04:32:44
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
CVE-2019-17670
- EPSS 6.32%
- Published 17.10.2019 13:15:10
- Last modified 21.11.2024 04:32:44
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
CVE-2019-17671
- EPSS 75.06%
- Published 17.10.2019 13:15:10
- Last modified 21.11.2024 04:32:44
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
CVE-2019-17666
- EPSS 0.45%
- Published 17.10.2019 02:15:13
- Last modified 21.11.2024 04:32:44
rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
CVE-2019-2992
- EPSS 0.91%
- Published 16.10.2019 18:15:33
- Last modified 21.11.2024 04:41:56
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticate...
CVE-2019-2999
- EPSS 0.48%
- Published 16.10.2019 18:15:33
- Last modified 21.11.2024 04:41:57
Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via mul...
CVE-2019-2975
- EPSS 0.78%
- Published 16.10.2019 18:15:32
- Last modified 21.11.2024 04:41:54
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticate...