4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-58288
Genexus Protection Server Windows
8.7
HIGH
EPSS
0.1%
2024 CWE-428 1 PoC

Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations.

CVE-2019-25352
Crystal Live HTTP Server Web Windows
8.7
HIGH
EPSS
0.6%
2019 CWE-22 1 PoC

Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files.

CVE-2025-61666
traccar Windows ⚡ nuclei
8.7
HIGH
EPSS
1.4%
2025 CWE-22 0 PoCs

Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to leakage of passwords or any file on the file system including the Traccar configuration file. Versions 5.8 - 6.0 are only vulnerable if <entry key='web.override'>./override</entry> is set in the configuration file. Versions 6.1 - 6.8.1 are vulnerable by default as the web override is enabled by default. The vulnerable code is removed in version 6.9.0

CVE-2025-34126
RIPS Scanner Web Windows
8.7
HIGH
EPSS
73.6%
2025 CWE-22 2 PoCs

A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system with the privileges of the web server by sending crafted HTTP GET requests to the 'windows/code.php' script with a manipulated 'file' parameter. This can lead to disclosure of sensitive information.

CVE-2025-7771
ThrottleStop Web Windows
8.7
HIGH
EPSS
0.2%
2025 CWE-782 2 PoCs

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbitrary code in kernel context, resulting in privilege escalation and potential follow-on attacks, such as disabling security software or bypassing kernel-level protections. ThrottleStop.sys version 3.0.

CVE-2025-4660
SecureConnector Windows
8.7
HIGH
EPSS
1.5%
2025 CWE-276 1 PoC

A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent.  This does not impact Linux or OSX Secure Connector.

CVE-2020-11026
WordPress Web Windows
8.7
HIGH
EPSS
4.4%
2020 CWE-707 1 PoC

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVE-2010-10012
httpdasm Web Windows
8.7
HIGH
EPSS
61.8%
2010 CWE-22 3 PoCs

A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specially crafted GET request containing a sequence of URL-encoded backslashes and directory traversal patterns, an attacker can escape the web root and access sensitive files outside of the intended directory.

CVE-2011-10028
RealArcade ActiveX Windows
8.7
HIGH
EPSS
62.6%
2011 CWE-623 4 PoCs

The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.

CVE-2021-47959
WPGraphQL Web Database Windows
8.7
HIGH
EPSS
0.0%
2021 CWE-770 1 PoC

WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads to trigger server out-of-memory conditions and MySQL connection errors.

CVE-2026-3830
Product Filter for WooCommerce by WBW Web Database Windows
8.6
HIGH
EPSS
0.1%
2026 1 PoC

The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2023-39423
IRM Next Generation Web Database Windows
8.6
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

CVE-2023-2318
MarkText Web Windows
8.6
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies text from a malicious webpage and paste it into MarkText.

CVE-2023-53958
LDAP Tool Box Self Service Password Web Windows
8.6
HIGH
EPSS
0.1%
2023 CWE-640 1 PoC

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.

CVE-2023-43662
ShokoServer Web Windows ⚡ nuclei
8.6
HIGH
EPSS
91.9%
2023 CWE-22 0 PoCs

ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without authentication and is supposed to return default server images. The endpoint accepts the parameter `serverImagePath`, which is not sanitized in any way before being passed to `System.IO.File.OpenRead`, which results in an arbitrary file read. This issue may lead to an arbitrary file read which is exacerbated in the windows installer which installs the ShokoServer as administrator. Any unauthenticated attacker may be able to access sensitive informat

CVE-2023-2317
Typora Web Windows
8.6
HIGH
EPSS
49.3%
2023 CWE-79 1 PoC

DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in <embed> tag. This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.

CVE-2023-6360
Software Genérico Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
84.6%
2023 CWE-89 2 PoCs

The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.

CVE-2024-13617
aoa-downloadable Web Windows
8.6
HIGH
EPSS
0.3%
2024 1 PoC

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

CVE-2024-9495
CP210x VCP Windows Windows
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210x VCP Windows installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-9186
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
32.7%
2024 1 PoC

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks