4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-7308
McAfee Endpoint Security (ENS) for WIndows Windows
4.8
MEDIUM
EPSS
0.1%
2020 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an attacker to intercept requests and send their own responses.

CVE-2020-7275
McAfee Endpoint Security (ENS) Windows
4.8
MEDIUM
EPSS
0.1%
2020 CWE-428 1 PoC

Accessing, modifying or executing executable files vulnerability in the uninstaller in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to execute arbitrary code via a carefully crafted input file.

CVE-2010-5175
Software Genérico Networking Windows
4.8
MEDIUM
EPSS
0.1%
2010 3 PoCs

Race condition in PrivateFirewall 7.0.20.37 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVE-2022-3539
Testimonials Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3862
Livemesh Addons for Elementor Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3392
WP Humans.txt Web Windows
4.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3906
Easy Form Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-2983
Salat Times Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3631
OAuth Client by DigitialPixies Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-4243
ImageInject Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The ImageInject WordPress plugin through 1.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3922
Broken Link Checker Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1094
amr users Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3831
reCAPTCHA Web Windows
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3070
Generate PDF using Contact Form 7 Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3834
Google Forms Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4199
Link Library Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3420
Official Integration for Billingo Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.

CVE-2022-3822
Donations via PayPal Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3391
Retain Live Chat Web Windows
4.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3753
Evaluate Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).