4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-4573
Mattermost Web Windows
4.1
MEDIUM
EPSS
0.2%
2025 CWE-90 1 PoC

Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT /api/v4/ldap/groups/{remote_id}/link API when objectGUID is configured as the Group ID Attribute.

CVE-2025-3951
WP-Optimize Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.

CVE-2020-1778
OTRS Windows
4.1
MEDIUM
EPSS
0.2%
2020 CWE-287 1 PoC

When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.

CVE-2024-4755
Google CSE Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5473
Simple Photoswipe Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2021-23883
Endpoint Security (ENS) for Windows Windows
4.0
MEDIUM
EPSS
0.1%
2021 CWE-476 1 PoC

A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to this update.

CVE-2020-15279
Endpoint Security Tools for Windows Windows
4.0
MEDIUM
EPSS
0.1%
2020 CWE-284 1 PoC

An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.

CVE-2022-28790
Link to Windows Service Windows
4.0
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.