2040 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-2221
WP Custom Cursors | WordPress Cursor Plugin Web Database Windows
7.2
HIGH
EPSS
0.2%
2023 2 PoCs

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2023-4861
File Manager Pro Web Windows
7.2
HIGH
EPSS
4.3%
2023 1 PoC

The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.

CVE-2023-1425
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins

CVE-2023-2298
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
7.2
HIGH
EPSS
1.8%
2023 CWE-79 1 PoC

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-4300
Import XML and RSS Feeds Web Windows
7.2
HIGH
EPSS
12.0%
2023 2 PoCs

The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.

CVE-2023-50916
Software Genérico Windows
7.2
HIGH
EPSS
0.3%
2023 2 PoCs

Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a UNC path. It allows administrators to configure the backup location of the database used by the application. Attempting to change this location to a UNC path via the GUI is rejected due to the use of a \ (backslash) character, which is supposed to be disallowed in a pathname. Intercepting and modifying this request via a proxy, or sending the request directly to the application endpoint, allows UNC paths to be set for the backup location. Once such

CVE-2023-0278
GeoDirectory Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-0277
WC Fields Factory Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-0924
ZYREX POPUP Web Windows
7.2
HIGH
EPSS
1.0%
2023 1 PoC

The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install.

CVE-2023-22883
Zoom Client for Meetings for IT Admin Windows installers Windows
7.2
HIGH
EPSS
0.1%
2023 CWE-367 1 PoC

Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to the SYSTEM user.

CVE-2023-7082
Import any XML or CSV File to WordPress Web Windows
7.2
HIGH
EPSS
3.5%
2023 1 PoC

The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessible directory without sufficiently validating the extracted file type. This may allows high privilege users such as administrator to upload an executable file type leading to remote code execution.

CVE-2023-31702
Software Genérico Database Windows
7.2
HIGH
EPSS
2.4%
2023 3 PoCs

SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1.

CVE-2023-1912
Limit Login Attempts Web Windows
7.2
HIGH
EPSS
5.3%
2023 CWE-79 2 PoCs

The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin's settings page. This only works when the plugin prioritizes use of the X-FORWARDED-FOR header, which can be configured in its settings.

CVE-2023-0487
All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-23550
UR32L Windows
7.2
HIGH
EPSS
0.3%
2023 CWE-77 2 PoCs

An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-0279
Media Library Assistant Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-4797
Newsletters Web Database Windows
7.2
HIGH
EPSS
0.6%
2023 1 PoC

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

CVE-2023-4691
WordPress Online Booking and Scheduling Plugin Web Database Windows
7.2
HIGH
EPSS
0.2%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-22365
UR32L Windows
7.2
HIGH
EPSS
0.2%
2023 CWE-78 2 PoCs

An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted set of network packets can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-1124
Shopping Cart & eCommerce Store Web Windows
7.2
HIGH
EPSS
1.1%
2023 1 PoC

The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.