4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-23277
Microsoft Exchange Server 2013 Cumulative Update 23 Windows
8.8
HIGH
EPSS
79.1%
2022 2 PoCs

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2022-22744
Firefox ESR Windows
8.8
HIGH
EPSS
0.4%
2022 1 PoC

The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVE-2022-3852
VR Calendar Web Windows
8.8
HIGH
EPSS
0.4%
2022 CWE-352 1 PoC

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2022-22629
Safari Windows
8.8
HIGH
EPSS
21.7%
2022 2 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-41080
🔥 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.8
HIGH
EPSS
93.8%
2022 1 PoC

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2022-3860
Visual Email Designer for WooCommerce Web Database Windows
8.8
HIGH
EPSS
0.7%
2022 1 PoC

The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.

CVE-2022-26927
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
28.1%
2022 2 PoCs

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2022-4237
Welcart e-Commerce Web Windows
8.8
HIGH
EPSS
1.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscriber to perform PHAR deserialisation when they can upload a file and a suitable gadget chain is present on the blog

CVE-2006-3730
Software Genérico Windows
8.8
HIGH
EPSS
86.9%
2006 2 PoCs

Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.

CVE-2021-47941
Survey & Poll Web Database Windows
8.8
HIGH
EPSS
0.1%
2021 CWE-89 1 PoC

WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database information including usernames, passwords, and other confidential data from the WordPress database.

CVE-2013-10035
ProcessMaker Open Source Web Windows
8.7
HIGH
EPSS
41.9%
2013 CWE-94 2 PoCs

A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin. An authenticated user can execute arbitrary PHP code via multiple endpoints, including appFolderAjax.php, casesStartPage_Ajax.php, and cases_SchedulerGetPlugins.php, by supplying crafted POST requests to parameters such as action and params. These endpoints fail to validate user input and directly invoke PHP functions like system() with user-supplied parameters, enabling remote code execution. The vulnerability affects both Linux and Windows installations and is present in d

CVE-2013-10065
Multi-Server Networking Windows
8.7
HIGH
EPSS
53.1%
2013 CWE-248 1 PoC

A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of malformed key exchange data, including a non-standard byte (\x28) in place of the expected SSH protocol delimiter.

CVE-2026-30791
RustDesk Client Windows
8.7
HIGH
EPSS
0.0%
2026 CWE-327 1 PoC

Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files flutter/lib/common.Dart, hbb_common/src/config.Rs and program routines parseRustdeskUri(), importConfig(). This issue affects RustDesk Client: through 1.4.5.

CVE-2026-30796
RustDesk Server Pro Web Windows
8.7
HIGH
EPSS
0.0%
2026 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sync API modules) allows Sniffing Attacks. This vulnerability is associated with program files Closed source — API endpoint handling heartbeat sync and program routines Heartbeat API handler (accepts preset-address-book-password in plaintext). This issue affects RustDesk Server Pro: through 1.7.5.

CVE-2026-30795
RustDesk Client Web Windows
8.7
HIGH
EPSS
0.0%
2026 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines Heartbeat JSON payload construction (preset-address-book-password). This issue affects RustDesk Client: through 1.4.5.

CVE-2026-3598
RustDesk Server Pro Windows
8.7
HIGH
EPSS
0.0%
2026 CWE-327 1 PoC

Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program routines Config export/generation routines. This issue affects RustDesk Server Pro: through 1.7.5.

CVE-2023-34120
Zoom for Windows Client Windows
8.7
HIGH
EPSS
0.0%
2023 CWE-347 1 PoC

Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.

CVE-2024-2739
Advanced Search Web Windows
8.7
HIGH
EPSS
0.3%
2024 1 PoC

The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-6911
ProcessPlus Windows ⚡ nuclei
8.7
HIGH
EPSS
93.3%
2024 CWE-552 2 PoCs

Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-3594
IDonate Web Windows
8.7
HIGH
EPSS
1.0%
2024 1 PoC

The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)