4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-42548
Share-one-Drive Web Windows
4.7
MEDIUM
EPSS
0.8%
2021 CWE-79 1 PoC

Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

CVE-2025-68947
NSecKrnl Windows
4.7
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

CVE-2025-9487
Admin and Site Enhancements (ASE) Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc.php when such uploads are enabled, which could allow users to upload a malicious SVG containing XSS payloads

CVE-2025-9540
Markup Markdown Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-12569
Guest posting / Frontend Posting / Front Editor Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2025-9541
Markup Markdown Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-0522
LikeBot Web Windows
4.7
MEDIUM
EPSS
0.1%
2025 1 PoC

The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2025-4955
tarteaucitron.io Web Windows
4.7
MEDIUM
EPSS
0.3%
2025 1 PoC

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVE-2020-14746
Applications Framework Web Database Windows
4.7
MEDIUM
EPSS
0.7%
2020 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popup windows). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update,

CVE-2020-7322
Endpoint Security for Windows Windows
4.7
MEDIUM
EPSS
0.1%
2020 CWE-532 1 PoC

Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly logging of sensitive information in debug logs.

CVE-2022-34704
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
3.3%
2022 1 PoC

Windows Defender Credential Guard Information Disclosure Vulnerability

CVE-2022-2546
All-in-One WP Migration Web Windows ⚡ nuclei
4.7
MEDIUM
EPSS
16.2%
2022 5 PoCs

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

CVE-2023-28345
Software Genérico Web Windows
4.6
MEDIUM
EPSS
0.0%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console can open a web browser, navigate to the affected endpoint and obtain the teacher's password. This enables them to log into the Teacher Console and begin trivially attacking student machines.

CVE-2024-13096
WP Finance Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-6362
Ultimate Blocks Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-2218
LuckyWP Table of Contents Web Windows
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13126
Download Manager Web Windows ⚡ nuclei
4.6
MEDIUM
EPSS
1.5%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

CVE-2024-4271
SVGator Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-3993
AZAN Plugin Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack