4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-28188
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service.

CVE-2022-28187
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.0%
2022 CWE-772 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where the memory management software does not release a resource after its effective lifetime has ended, which may lead to denial of service.

CVE-2022-28190
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where improper input validation can cause denial of service.

CVE-2025-21844
Linux Windows
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of cifs_buf_get() and cifs_small_buf_get() in receive_encrypted_standard() to prevent null pointer dereference.

CVE-2026-2712
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance Web Windows
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smush_Manager_Commands` methods without verifying user capabilities, nonce tokens, or the allowed commands whitelist that the normal AJAX handler (`updraft_smush_ajax`) enforces. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke ad

CVE-2026-0903
Chrome Windows
5.4
MEDIUM
EPSS
0.0%
2026 CWE-20 1 PoC

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protections via a malicious file. (Chromium security severity: Medium)

CVE-2026-5306
Check & Log Email Web Windows
5.4
MEDIUM
EPSS
0.1%
2026 1 PoC

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled

CVE-2023-5087
Page Builder: Pagelayer Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.

CVE-2023-0535
Donation Block For PayPal Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0280
Ultimate Carousel For Elementor Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-5237
Memberlite Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.5%
2023 2 PoCs

The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2023-0366
Loan Comparison Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-4646
Simple Posts Ticker Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-3746
ActivityPub Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

CVE-2023-5167
user-activity-log-pro Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.

CVE-2023-0060
Responsive Gallery Grid Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0399
Image Over Image For WPBakery Page Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0542
Custom Post Type List Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0072
WC Vendors Marketplace Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0033
PDF Viewer Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.