4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-21306
Windows Server 2022 Windows
5.7
MEDIUM
EPSS
30.1%
2024 CWE-306 1 PoC

Microsoft Bluetooth Driver Spoofing Vulnerability

CVE-2022-22312
Security Verify Password Synchronization Plug-in for Windows AD Windows
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 217369.

CVE-2022-3881
WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log Web Windows
5.7
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-2355
Easy Username Updater Web Windows
5.7
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin

CVE-2022-22323
Security Verify Password Synchronization Plug-in for Windows AD Windows
5.7
MEDIUM
EPSS
0.6%
2022 1 PoC

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 218379.

CVE-2024-6978
SDP Client Windows
5.6
MEDIUM
EPSS
0.1%
2024 CWE-20 1 PoC

Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.

CVE-2019-3610
True Key (TK) Windows
5.6
MEDIUM
EPSS
0.0%
2019 1 PoC

Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidential data via specially crafted malware.

CVE-2019-1125
Windows 10 Version 1703 Windows
5.6
MEDIUM
EPSS
19.2%
2019 2 PoCs

An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory an

CVE-2021-31836
McAfee Agent for Windows Windows
5.6
MEDIUM
EPSS
0.1%
2021 CWE-269 1 PoC

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

CVE-2025-9115
Etsy Shop Web Windows
5.6
MEDIUM
EPSS
0.0%
2025 1 PoC

The Etsy Shop WordPress plugin before 3.0.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.

CVE-2013-3900
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
74.4%
2013 CWE-347 12 PoCs

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verificatio

CVE-2015-10027
TTRSS-Auth-LDAP Windows
5.5
MEDIUM
EPSS
1.0%
2015 CWE-90 1 PoC

A vulnerability, which was classified as problematic, has been found in hydrian TTRSS-Auth-LDAP. Affected by this issue is some unknown functionality of the component Username Handler. The manipulation leads to ldap injection. Upgrading to version 2.0b1 is able to address this issue. The patch is identified as a7f7a5a82d9202a5c40d606a5c519ba61b224eb8. It is recommended to upgrade the affected component. VDB-217622 is the identifier assigned to this vulnerability.

CVE-2026-6867
Wireshark Windows
5.5
MEDIUM
EPSS
0.0%
2026 CWE-1325 1 PoC

SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-5407
Wireshark Windows
5.5
MEDIUM
EPSS
0.0%
2026 CWE-835 2 PoCs

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2023-51778
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

CVE-2023-21899
VM VirtualBox Database Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. Note: Applies to VirtualBox VMs running Windows 7 and later. CVSS 3.1 Base Score 5.5 (Availabi

CVE-2023-21776
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
1.9%
2023 CWE-125 2 PoCs

Windows Kernel Information Disclosure Vulnerability

CVE-2023-36404
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2023-21898
VM VirtualBox Database Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. Note: Applies to VirtualBox VMs running Windows 7 and later. CVSS 3.1 Base Score 5.5 (Availabi

CVE-2023-22017
VM VirtualBox Database Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.46 and Prior to 7.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. Note: This vulnerability applies to Windows VMs only. CVSS 3.1 Base Score 5.5 (Availability i