4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-3919
OpenPGP Form Encryption for WordPress Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2021-40836
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit) F-Secure Linux Security 64 F-Secure Atlant & F-Secure Internet Gatekeeper Windows
4.6
MEDIUM
EPSS
0.1%
2021 1 PoC

A vulnerability affecting F-Secure antivirus engine was discovered whereby scanning MS outlook .pst files can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

CVE-2021-47818
DupTerminator Windows
4.6
MEDIUM
EPSS
0.0%
2021 CWE-1284 1 PoC

DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application by inputting a long character string in the Excluded text box. Attackers can generate a payload of 8000 repeated characters to trigger the application to stop working on Windows 10.

CVE-2021-33598
F-Secure endpoint protection products on Windows, Mac and Linux Security Web Windows
4.6
MEDIUM
EPSS
0.4%
2021 1 PoC

A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

CVE-2021-40837
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit), F-Secure Linux Security 64, F-Secure Atlant, F-Secure Internet Gatekeeper & F-Secure Security Cloud Cloud Windows
4.6
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

CVE-2020-7279
McAfee Host Intrusion Prevention System (Host IPS) for Windows Windows
4.6
MEDIUM
EPSS
0.2%
2020 CWE-426 1 PoC

DLL Search Order Hijacking Vulnerability in the installer component of McAfee Host Intrusion Prevention System (Host IPS) for Windows prior to 8.0.0 Patch 15 Update allows attackers with local access to execute arbitrary code via execution from a compromised folder.

CVE-2022-39050
OTRS Web Windows
4.6
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVE-2022-4562
Meks Flexible Shortcodes Web Windows
4.6
MEDIUM
EPSS
0.3%
2022 1 PoC

The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2024-2432
GlobalProtect App Networking Windows
4.5
MEDIUM
EPSS
0.4%
2024 CWE-269 2 PoCs

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

CVE-2024-3060
ENL Newsletter Web Database Windows
4.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks

CVE-2024-2405
Float menu Web Windows
4.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

CVE-2019-3641
Threat Intelligence Exchange Server (TIE Server) Web Windows
4.5
MEDIUM
EPSS
0.2%
2019 CWE-285 1 PoC

Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.

CVE-2025-3503
WP Maps Web Windows
4.5
MEDIUM
EPSS
0.2%
2025 1 PoC

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-10124
Booking Manager Web Windows
4.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.

CVE-2010-5160
Software Genérico Windows
4.5
MEDIUM
EPSS
0.1%
2010 3 PoCs

Race condition in ESET Smart Security 4.2.35.3 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVE-2022-1984
HYPR Windows WFA Windows
4.5
MEDIUM
EPSS
0.1%
2022 CWE-502 1 PoC

This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized payload.

CVE-2023-4636
File Sharing & Download Manager – User Private Files Web Windows
4.4
MEDIUM
EPSS
3.3%
2023 CWE-79 1 PoC

The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2023-5621
Thumbnail Slider With Lightbox Web Windows
4.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2023-1374
Solidres – Hotel booking plugin for WordPress Web Windows
4.4
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

The Solidres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'currency_name' parameter in versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.