4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-11320
Pandora FMS Windows ⚡ nuclei
6.9
MEDIUM
EPSS
92.6%
2024 CWE-77 2 PoCs

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

CVE-2024-3642
Newsletter Popup Web Windows
6.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack

CVE-2019-25485
R Windows
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the GUI Preferences language menu field that allows local attackers to bypass DEP and ASLR protections. Attackers can inject a crafted payload through the Language for menus preference to trigger a structured exception handler chain pivot and execute arbitrary shellcode with application privileges.

CVE-2020-7323
Endpoint Security for Windows Windows
6.9
MEDIUM
EPSS
0.1%
2020 CWE-287 1 PoC

Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain detection events while the computer screen is locked and the McTray.exe is running with elevated privileges. This issue is timing dependent and requires physical access to the machine.

CVE-2022-50956
amministrazione-aperta Web Windows
6.9
MEDIUM
EPSS
0.0%
2022 CWE-22 1 PoC

WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to include and read sensitive files accessible to the web server.

CVE-2026-1753
Gutena Forms Web Windows
6.8
MEDIUM
EPSS
0.0%
2026 1 PoC

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

CVE-2023-0075
Amazon JS Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0378
Greenshift Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0061
Judge.me Product Reviews for WooCommerce Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0375
Easy Affiliate Links Web Windows
6.8
MEDIUM
EPSS
0.7%
2023 1 PoC

The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0541
GS Books Showcase Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-30672
Samsung Smart Switch Windows
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.

CVE-2023-22880
Zoom for Windows Windows
6.8
MEDIUM
EPSS
0.5%
2023 CWE-200 1 PoC

Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s online Spellcheck service instead of the local Windows Spellcheck. Updating Zoom remediates this vulnerability by disabling the feature. Updating Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restarting Zoom remediates this vulnerability by updating Microsof

CVE-2024-5284
wp-affiliate-platform Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-10709
YaDisk Files Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-6021
Donation Block For PayPal Web Windows
6.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Donation Block For PayPal WordPress plugin through 2.1.0 does not sanitise and escape form submissions, leading to a stored cross-site scripting vulnerability

CVE-2024-2761
Genesis Blocks Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.

CVE-2024-5077
wp-eMember Web Windows
6.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-37085
🔥 KEV VMware ESXi Web Windows
6.8
MEDIUM
EPSS
75.1%
2024 4 PoCs

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

CVE-2024-6768
Windows 10 Windows
6.8
MEDIUM
EPSS
19.3%
2024 CWE-1284 4 PoCs

A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to the KeBugCheckEx function.