4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4369
WP-Lister Lite for Amazon Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high-privilege users such as admin.

CVE-2022-2404
WP Popup Builder – Popup Forms , Marketing PoPuP & Newsletter Web Windows
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-2669
WP Taxonomy Import Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-3484
wpb-show-core Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.5%
2022 CWE-79 1 PoC

The WPB Show Core WordPress plugin does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-3415
Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back Web Windows
6.1
MEDIUM
EPSS
1.1%
2022 CWE-79 1 PoC

The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message

CVE-2022-4453
3D FlipBook Web Windows
6.1
MEDIUM
EPSS
0.4%
2022 1 PoC

The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like administrators.

CVE-2022-4321
PDF Generator for WordPress Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.1%
2022 1 PoC

The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin

CVE-2022-4267
Bulk Delete Users by Email Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The Bulk Delete Users by Email WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-2654
Classified Listing – Classified ads & Business Directory Plugin Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting

CVE-2022-4307
پلاگین پرداخت دلخواه Web Windows
6.1
MEDIUM
EPSS
1.1%
2022 1 PoC

The پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenticated attackers to send a request with XSS payloads, which will be triggered when a high privilege users such as admin visits a page from the plugin.

CVE-2022-1257
McAfee Agent Windows
6.1
MEDIUM
EPSS
0.2%
2022 CWE-922 2 PoCs

Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.

CVE-2022-1617
WP-Invoice Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them

CVE-2022-4329
Product list Widget for Woocommerce Web Windows
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high privilege one like admin).

CVE-2022-4745
WP Customer Area Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

CVE-2025-15345
MapGeo – Interactive Geo Maps Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 CWE-80 1 PoC

The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-31026
vGPU driver and Cloud gaming driver Cloud Windows
6.0
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service.

CVE-2025-62522
vite Web Windows ⚡ nuclei
6.0
MEDIUM
EPSS
0.9%
2025 CWE-22 0 PoCs

Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.

CVE-2020-7326
McAfee Active Response Windows
6.0
MEDIUM
EPSS
0.1%
2020 CWE-290 1 PoC

Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MAR failing open rather than closed

CVE-2020-7327
McAfee MVISION Endpoint Detection and Response Windows
6.0
MEDIUM
EPSS
0.1%
2020 CWE-290 1 PoC

Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MVEDR failing open rather than closed

CVE-2020-7315
MA for Windows Windows
6.0
MEDIUM
EPSS
0.1%
2020 CWE-426 1 PoC

DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.