4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-40290
Software Genérico Web Windows
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows.

CVE-2024-9593
Time Clock Pro Web Windows ⚡ nuclei
8.3
HIGH
EPSS
85.5%
2024 CWE-94 3 PoCs

The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.

CVE-2024-4749
wp-eMember Web Windows
8.3
HIGH
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-11114
Chrome Windows
8.3
HIGH
EPSS
0.5%
2024 1 PoC

Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2019-20361
Software Genérico Web Database Windows
8.3
HIGH
EPSS
28.1%
2019 3 PoCs

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

CVE-2017-20192
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Web Windows ⚡ nuclei
8.3
HIGH
EPSS
28.7%
2017 CWE-79 1 PoC

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVE-2012-10018
Mapplic Lite Web Windows ⚡ nuclei
8.3
HIGH
EPSS
3.4%
2012 CWE-918 2 PoCs

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

CVE-2025-2783
🔥 KEV Chrome Windows
8.3
HIGH
EPSS
46.9%
2025 2 PoCs

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVE-2025-3776
Verification SMS with TargetSMS Web Windows
8.3
HIGH
EPSS
0.7%
2025 CWE-94 1 PoC

The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo().

CVE-2020-36730
CMP – Coming Soon & Maintenance Plugin by NiteoThemes Web Windows
8.3
HIGH
EPSS
46.4%
2020 CWE-862 2 PoCs

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.

CVE-2020-15841
Software Genérico Windows
8.3
HIGH
EPSS
0.3%
2020 1 PoC

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.

CVE-2022-37397
Yugabyte DB Windows
8.3
HIGH
EPSS
0.5%
2022 CWE-287 1 PoC

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

CVE-2022-0218
WP HTML Mail Web Windows ⚡ nuclei
8.3
HIGH
EPSS
62.4%
2022 CWE-862 0 PoCs

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.

CVE-2015-2546
🔥 KEV Software Genérico Windows
8.2
HIGH
EPSS
43.5%
2015 1 PoC

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.

CVE-2026-30785
RustDesk Client Windows
8.2
HIGH
EPSS
0.0%
2026 CWE-257 1 PoC

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config encryption, machine UID modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files hbb_common/src/password_security.Rs, hbb_common/src/config.Rs, hbb_common/src/lib.Rs (get_uuid), machine-uid/src/lib.Rs and program routines symmetric_crypt(), encrypt_str_or_original(), decrypt

CVE-2026-30798
RustDesk Client Web Windows
8.2
HIGH
EPSS
0.0%
2026 CWE-345 1 PoC

Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines stop-service handler in heartbeat loop. This issue affects RustDesk Client: through 1.4.5.

CVE-2023-34116
Zoom Desktop Client for Windows Windows
8.2
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.

CVE-2023-34119
Zoom Rooms for Windows Windows
8.2
HIGH
EPSS
0.1%
2023 CWE-426 1 PoC

Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-36536
Zoom Rooms for Windows Windows
8.2
HIGH
EPSS
0.1%
2023 CWE-426 1 PoC

Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-31027
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
8.2
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.