4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-2916
InfiniteWP Client Web Windows
7.5
HIGH
EPSS
29.5%
2023 CWE-200 1 PoC

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.

CVE-2023-51070
Software Genérico Windows
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.

CVE-2023-0812
Active Directory Integration / LDAP Integration Web Windows
7.5
HIGH
EPSS
0.4%
2023 1 PoC

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.

CVE-2023-3525
Getnet Argentina para Woocommerce Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.

CVE-2023-21893
Data Provider for .NET Database Windows
7.5
HIGH
EPSS
1.1%
2023 1 PoC

Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Data Provider for .NET. Note: Applies also to Database client-only on Windows platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability

CVE-2023-6584
WP JobSearch Web Windows
7.5
HIGH
EPSS
0.3%
2023 1 PoC

The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.

CVE-2023-6294
Popup Builder Web Windows
7.5
HIGH
EPSS
0.3%
2023 1 PoC

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

CVE-2023-6113
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated attackers to download said backups later.

CVE-2023-7269
ArtPlacer Widget Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-2180
KIWIZ Invoices Certification & PDF System Web Windows
7.5
HIGH
EPSS
0.6%
2023 1 PoC

The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)

CVE-2023-30445
DB2 for Linux, UNIX and Windows Windows
7.5
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.

CVE-2023-0331
Correos Oficial Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.

CVE-2023-1405
Formidable Forms Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVE-2023-32113
SAP GUI for Windows Windows
7.5
HIGH
EPSS
0.2%
2023 CWE-200 1 PoC

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.

CVE-2023-5454
Templately Web Windows
7.5
HIGH
EPSS
0.8%
2023 1 PoC

The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.

CVE-2023-53875
GOM Player Windows
7.5
HIGH
EPSS
0.4%
2023 CWE-319 1 PoC

GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction.

CVE-2023-5003
Active Directory Integration / LDAP Integration Web Windows ⚡ nuclei
7.5
HIGH
EPSS
77.8%
2023 1 PoC

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

CVE-2023-0428
Watu Quiz Web Windows
7.5
HIGH
EPSS
0.7%
2023 1 PoC

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-5203
WP Sessions Time Monitoring Full Automatic Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
42.9%
2023 1 PoC

The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.

CVE-2023-7164
BackWPup Web Windows ⚡ nuclei
7.5
HIGH
EPSS
25.4%
2023 1 PoC

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.