4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-3098
Login Block IPs Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-3336
Event Monster Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack

CVE-2022-1760
Core Control Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Core Control WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-12855
AdForest Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 CWE-862 1 PoC

The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in all versions up to, and including, 5.1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete posts, attachments and deactivate a license.

CVE-2024-10782
Theme Builder For Elementor Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-639 1 PoC

The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

CVE-2024-38143
Windows 11 Version 24H2 Windows
4.2
MEDIUM
EPSS
4.3%
2024 CWE-306 1 PoC

Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

CVE-2024-10815
PostLists Web Windows
4.2
MEDIUM
EPSS
0.2%
2024 1 PoC

The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2019-3880
samba Web Windows
4.2
MEDIUM
EPSS
3.4%
2019 CWE-22 1 PoC

A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.

CVE-2020-7252
Data Exchange Layer (DXL) Broker Windows
4.2
MEDIUM
EPSS
0.2%
2020 CWE-250 1 PoC

Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.

CVE-2023-34121
Zoom for Windows Windows
4.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.

CVE-2024-10009
Melapress File Monitor Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-9689
Post From Frontend Web Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack

CVE-2024-12109
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-9828
Taskbuilder Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks

CVE-2024-10638
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2025-1986
Gutentor Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Gutentor WordPress plugin before 3.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2025-1446
Pods Web Database Windows
4.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2025-13001
donation Web Database Windows
4.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such as admin to perform SQL injection attacks

CVE-2025-2048
Lana Downloads Manager Web Windows
4.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server

CVE-2025-3943
Niagara Framework Windows
4.1
MEDIUM
EPSS
0.4%
2025 CWE-598 1 PoC

Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.