4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-2834
Helpful Web Windows
5.3
MEDIUM
EPSS
0.5%
2022 1 PoC

The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings

CVE-2022-1613
Restricted Site Access Web Windows
5.3
MEDIUM
EPSS
0.2%
2022 CWE-639 1 PoC

The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.

CVE-2022-4340
BookingPress Web Windows
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.

CVE-2022-4057
Autoptimize Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
45.4%
2022 1 PoC

The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.

CVE-2022-2461
Transposh WordPress Translation Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
16.9%
2022 CWE-862 2 PoCs

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.

CVE-2022-4539
Web Application Firewall – website security Web Networking Windows
5.3
MEDIUM
EPSS
5.1%
2022 CWE-348 1 PoC

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.

CVE-2022-33901
MultiSafepay plugin for WooCommerce (WordPress plugin) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
10.2%
2022 0 PoCs

Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.

CVE-2022-4429
Avira Security for Windows Windows
5.3
MEDIUM
EPSS
0.0%
2022 CWE-428 1 PoC

Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges to cause a Denial of Service. The issue was fixed with Avira Security version 1.1.78

CVE-2022-4097
All-In-One Security (AIOS) Web Windows
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more).

CVE-2022-4417
WP Cerber Security, Anti-spam & Malware Scan Web Windows
5.3
MEDIUM
EPSS
0.4%
2022 1 PoC

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users

CVE-2022-28779
Samsung Android USB Driver windows installer Windows
5.3
MEDIUM
EPSS
0.1%
2022 CWE-427 1 PoC

Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.

CVE-2022-1563
wp-graphql-woocommerce Web Windows
5.3
MEDIUM
EPSS
0.6%
2022 1 PoC

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

CVE-2022-3489
Wp-Hide Web Windows
5.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request

CVE-2022-4346
All-In-One Security (AIOS) Web Windows
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.

CVE-2024-3481
Counter Box Web Windows
5.2
MEDIUM
EPSS
0.1%
2024 1 PoC

The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks

CVE-2024-9473
GlobalProtect App Networking Windows
5.2
MEDIUM
EPSS
0.3%
2024 CWE-250 2 PoCs

A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect.

CVE-2024-41955
Mobile-Security-Framework-MobSF Windows ⚡ nuclei
5.2
MEDIUM
EPSS
14.8%
2024 CWE-601 0 PoCs

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.

CVE-2021-31832
McAfee Data Loss Prevention (DLP) Endpoint for Windows Web Windows
5.2
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

Improper Neutralization of Input in the ePO administrator extension for McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a remote ePO DLP administrator to inject JavaScript code into the alert configuration text field. This JavaScript will be executed when an end user triggers a DLP policy on their machine.

CVE-2018-10918
samba Windows
5.2
MEDIUM
EPSS
4.3%
2018 CWE-476 1 PoC

A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versions before 4.7.9 and 4.8.4 are vulnerable.

CVE-2023-54358
WordPress adivaha Travel Plugin Web Windows
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.