4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-28208
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.4%
2021 CWE-22 1 PoC

The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

CVE-2021-28196
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.6%
2021 CWE-120 1 PoC

The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28177
BMC firmware for Z10PR-D16 Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The LDAP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28192
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The specific function in ASUS BMC’s firmware Web management page (Remote video storage function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28202
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The Service configuration-2 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28197
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28190
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.6%
2021 CWE-120 1 PoC

The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28184
BMC firmware for Z10PR-D16 Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28194
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The specific function in ASUS BMC’s firmware Web management page (Remote image configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28207
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.4%
2021 CWE-22 1 PoC

The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

CVE-2021-28198
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28195
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-28200
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2025-3470
TS Poll – Survey, Versus Poll, Image Poll, Video Poll Web Database Windows
4.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-9345
File Manager, Code Editor, and Backup by Managefy Web Windows
4.9
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory.

CVE-2025-12630
Upload.am Web Windows
4.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

CVE-2025-3471
SureForms Web Windows
4.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action

CVE-2025-10046
ELEX WooCommerce Google Shopping (Google Product Feed) Web Database Windows
4.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-14719
Relevanssi Web Database Windows
4.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVE-2020-14869
MySQL Server Database Windows
4.9
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).