4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-11046
FreeRDP Windows
5.5
MEDIUM
EPSS
0.1%
2020 CWE-119 1 PoC

In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.

CVE-2018-15437
Cisco AMP for Endpoints Networking Windows
5.5
MEDIUM
EPSS
0.7%
2018 CWE-400 1 PoC

A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executable files to be launched on the system without being analyzed for threats. The vulnerability is due to improper process resource handling. An attacker could exploit this vulnerability by gaining local access to a system running Microsoft Windows and protected by Cisco Immunet or Cisco AMP for Endpoints and executing a malicious file. A su

CVE-2022-34710
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.7%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-24823
netty Web Windows
5.5
MEDIUM
EPSS
0.4%
2022 CWE-668 1 PoC

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system tempora

CVE-2022-34712
Windows 10 Version 21H1 Windows
5.5
MEDIUM
EPSS
4.2%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-34708
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2022 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2022-21533
Solaris Operating System Database Windows
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: SMB Server). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-28189
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a NULL pointer dereference may lead to a system crash.

CVE-2022-2941
WP-UserOnline Web Windows
5.5
MEDIUM
EPSS
5.2%
2022 CWE-79 2 PoCs

The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due to the fact that all fields in the "Naming Conventions" section do not properly sanitize user input, nor escape it on output. This makes it possible for authenticated attackers, with administrative privileges, to inject JavaScript code into the setting that will execute whenever a user accesses the injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2022-3690
Popup Maker Web Windows
5.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins

CVE-2022-41205
SAP GUI for Windows Windows
5.5
MEDIUM
EPSS
0.2%
2022 CWE-94 1 PoC

SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application.

CVE-2022-30155
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2022 1 PoC

Windows Kernel Denial of Service Vulnerability

CVE-2022-42266
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can cause exposure of sensitive information to an actor that is not explicitly authorized to have access to that information, which may lead to limited information disclosure.

CVE-2022-36314
Firefox ESR Windows
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.

CVE-2022-34683
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 2 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service.

CVE-2022-2473
WP-UserOnline Web Windows
5.5
MEDIUM
EPSS
1.0%
2022 CWE-79 3 PoCs

The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The only affects multi-site installations and installations where unfiltered_html is disabled.

CVE-2022-34681
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a display-related data structure may lead to denial of service.

CVE-2022-21877
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
15.0%
2022 1 PoC

Storage Spaces Controller Information Disclosure Vulnerability

CVE-2022-24483
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
5.9%
2022 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2022-46692
iCloud for Windows Cloud Windows
5.5
MEDIUM
EPSS
0.0%
2022 5 PoCs

A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.