4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-3265
Advanced Search Web Database Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.

CVE-2024-2428
The Ultimate Video Player For WordPress Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks

CVE-2024-6723
AI Engine Web Database Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.

CVE-2024-5032
SULly Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-6055
Remote Desktop Manager Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file.

CVE-2024-3703
Carousel Slider Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide shortcode is embed, which could allow users with the Editor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-12595
AHAthat Plugin Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-10568
Ajax Search Lite Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13608
Track Logins Web Database Windows
4.7
MEDIUM
EPSS
0.0%
2024 1 PoC

The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-0844
Popup More Popups, Lightboxes, and more popup modules Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary files ending with "Form.php" on the server , allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-13627
OWL Carousel Slider Web Windows ⚡ nuclei
4.7
MEDIUM
EPSS
2.3%
2024 1 PoC

The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-9770
WP-Recall Web Database Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-2102
Salon booking system Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field and 'sms_prefix' parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Bookings' page and the malicious script is executed in the admin context.

CVE-2024-5883
Ultimate Classified Listings Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-42547
Out-of-the-Box Web Windows
4.7
MEDIUM
EPSS
0.8%
2021 CWE-79 1 PoC

Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

CVE-2021-42205
Software Genérico Windows
4.7
MEDIUM
EPSS
0.1%
2021 1 PoC

ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.

CVE-2021-34420
Zoom Client for Meetings for Windows Windows
4.7
MEDIUM
EPSS
0.1%
2021 1 PoC

The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.

CVE-2021-42546
Use-Your-Drive Web Windows
4.7
MEDIUM
EPSS
0.8%
2021 CWE-79 1 PoC

Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

CVE-2021-1117
NVIDIA GPU Display Driver Windows
4.7
MEDIUM
EPSS
0.0%
2021 CWE-129 1 PoC

Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.

CVE-2021-42549
Lets-Box Web Windows
4.7
MEDIUM
EPSS
0.8%
2021 CWE-79 1 PoC

Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.