230 vulnerabilidades · Windows · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2020-3153
🔥 KEV Cisco AnyConnect Secure Mobility Client Networking Windows
6.5
MEDIUM
EPSS
25.1%
2020 CWE-427 6 PoCs

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related a

CVE-2026-21525
🔥 KEV Windows 10 Version 1607 Windows
6.2
MEDIUM
EPSS
9.4%
2026 CWE-476 2 PoCs

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

CVE-2019-9978
🔥 KEV Software Genérico Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
87.6%
2019 20 PoCs

The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

CVE-2013-3900
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
74.4%
2013 CWE-347 12 PoCs

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verificatio

CVE-2021-31955
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.1%
2021 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2020-1472
🔥 KEV Windows Server version 2004 Windows
5.5
MEDIUM
EPSS
94.4%
2020 59 PoCs

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by

CVE-2024-38217
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
12.1%
2024 CWE-693 1 PoC

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2021-26829
🔥 KEV Software Genérico Web Windows
5.4
MEDIUM
EPSS
7.6%
2021 2 PoCs

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

CVE-2022-41049
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
13.1%
2022 3 PoCs

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2018-13374
🔥 KEV Fortinet FortiOS, fortiADC Networking Windows
4.3
MEDIUM
EPSS
3.8%
2018 1 PoC

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.