4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-2179
WooCommerce Order Status Change Notifier Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

CVE-2023-29324
Windows 10 Version 1809 Windows
6.5
MEDIUM
EPSS
1.9%
2023 CWE-73 1 PoC

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2023-1430
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution Web Windows
6.5
MEDIUM
EPSS
1.6%
2023 CWE-759 1 PoC

The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.8.01 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.

CVE-2023-1129
WP FEvents Book Web Windows
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.

CVE-2023-0749
Ocean Extra Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

CVE-2023-7201
Everest Backup Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2023-6139
Essential Real Estate Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.

CVE-2023-7268
ArtPlacer Widget Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets

CVE-2023-1624
WPCode Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog folders

CVE-2023-4013
GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

CVE-2023-0491
Schedulicity Web Windows
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

The Schedulicity WordPress plugin through 2.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-22881
Zoom (for Android, iOS, Linux, macOS, and Windows) clients before version 5.13.5 Windows
6.5
MEDIUM
EPSS
0.8%
2023 CWE-119 1 PoC

Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.

CVE-2023-0501
WP Insurance Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-51071
Software Genérico Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.

CVE-2023-3508
WooCommerce Pre-Orders Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks

CVE-2024-43451
🔥 KEV Windows Server 2025 Windows
6.5
MEDIUM
EPSS
90.3%
2024 CWE-73 1 PoC

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-22532
Software Genérico Windows
6.5
MEDIUM
EPSS
5.1%
2024 1 PoC

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

CVE-2024-7135
Tainacan Web Windows
6.5
MEDIUM
EPSS
48.0%
2024 CWE-862 2 PoCs

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-5692
Firefox Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVE-2024-5071
Bookster Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.