4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13329
Solidres Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2019-3822
curl Web Windows
7.1
HIGH
EPSS
17.9%
2019 CWE-121 3 PoCs

libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header pro

CVE-2021-1090
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

CVE-2021-42110
Software Genérico Windows
7.1
HIGH
EPSS
0.1%
2021 2 PoCs

An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.

CVE-2021-36949
Microsoft Azure Active Directory Connect 1.X.Y.Z Cloud Windows
7.1
HIGH
EPSS
0.8%
2021 1 PoC

Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability

CVE-2021-1092
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in potential denial of service or data loss.

CVE-2021-43890
🔥 KEV App Installer Windows
7.1
HIGH
EPSS
25.2%
2021 3 PoCs

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative

CVE-2021-26088
Fortinet FSSO Windows DC Agent, FSSO Windows CA Networking Windows
7.1
HIGH
EPSS
5.5%
2021 1 PoC

An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.

CVE-2021-29447
wordpress-develop Web Windows
7.1
HIGH
EPSS
90.0%
2021 CWE-611 23 PoCs

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.

CVE-2021-1091
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service.

CVE-2009-2516
Software Genérico Windows
7.1
HIGH
EPSS
2.0%
2009 1 PoC

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."

CVE-2017-7482
kernel: Windows
7.1
HIGH
EPSS
0.2%
2017 CWE-190 1 PoC

In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.

CVE-2025-12629
Broken Link Manager Web Windows
7.1
HIGH
EPSS
0.0%
2025 1 PoC

The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-13355
URL Shortify Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-5034
wp-file-download Web Windows
7.1
HIGH
EPSS
0.2%
2025 1 PoC

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2025-1401
WP Click Info Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-12684
URL Shortify Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege users such as admins.

CVE-2025-13071
Custom Admin Menu Web Windows
7.1
HIGH
EPSS
0.0%
2025 1 PoC

The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-8281
WP Talroo Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users.

CVE-2025-13073
HandL UTM Grabber / Tracker Web Windows
7.1
HIGH
EPSS
0.0%
2025 1 PoC

The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin