4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-7421
Remote Desktop Manager Windows
5.5
MEDIUM
EPSS
0.1%
2024 CWE-532 1 PoC

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions

CVE-2024-22105
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.

CVE-2024-4759
Mime Types Extended Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-3824
Base64 Encoder/Decoder Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

CVE-2024-22104
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

CVE-2024-3048
Bannerlid Web Windows
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

CVE-2024-31211
wordpress-develop Web Windows
5.5
MEDIUM
EPSS
39.7%
2024 CWE-502 1 PoC

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.

CVE-2024-4934
Quiz and Survey Master (QSM) Web Windows
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-38041
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
16.7%
2024 CWE-200 2 PoCs

Windows Kernel Information Disclosure Vulnerability

CVE-2019-1153
Windows 10 Version 1703 Windows
5.5
MEDIUM
EPSS
2.8%
2019 1 PoC

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in memory.

CVE-2019-1148
Windows 10 Version 1703 Windows
5.5
MEDIUM
EPSS
4.2%
2019 1 PoC

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in memory.

CVE-2021-1699
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
0.8%
2021 1 PoC

Windows (modem.sys) Information Disclosure Vulnerability

CVE-2021-33602
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit) F-Secure Linux Security 64 F-Secure Atlant & F-Secure Cloud Protection for Salesforce Cloud Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZW decompression method), and this can crash the scanning engine. The vulnerability can be exploited remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine.

CVE-2021-31970
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.8%
2021 1 PoC

Windows TCP/IP Driver Security Feature Bypass Vulnerability

CVE-2021-34496
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2021 1 PoC

Windows GDI Information Disclosure Vulnerability

CVE-2021-24084
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.0%
2021 2 PoCs

Windows Mobile Device Management Information Disclosure Vulnerability

CVE-2021-1656
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
1.7%
2021 1 PoC

TPM Device Driver Information Disclosure Vulnerability

CVE-2021-24098
Windows 10 Version 2004 Windows
5.5
MEDIUM
EPSS
2.0%
2021 1 PoC

Windows Console Driver Denial of Service Vulnerability

CVE-2021-38926
DB2 for Linux, UNIX and Windows Windows
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.

CVE-2021-36873
iQ Block Country Web Windows ⚡ nuclei
5.5
MEDIUM
EPSS
1.8%
2021 CWE-79 0 PoCs

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.