2040 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4355
LetsRecover Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-3249
WP CSV Exporter Web Database Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks

CVE-2022-4370
multimedial images Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 2 PoCs

The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2022-1538
Theme Demo Import Web Windows
7.2
HIGH
EPSS
0.6%
2022 1 PoC

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed.

CVE-2022-3374
Ocean Extra Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

CVE-2022-2903
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Windows
7.2
HIGH
EPSS
0.8%
2022 CWE-502 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-4351
Qe SEO Handyman Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-4360
WP RSS By Publishers Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-3416
WPtouch Web Windows
7.2
HIGH
EPSS
1.2%
2022 1 PoC

The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2022-1540
PostmagThemes Demo Import Web Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.

CVE-2022-3856
Comic Book Management System Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The Comic Book Management System WordPress plugin before 2.2.0 does not sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2022-3720
Event Monster Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 1 PoC

The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users

CVE-2022-4371
Web Invoice Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well

CVE-2026-2466
DukaPress Web Windows
7.1
HIGH
EPSS
0.0%
2026 1 PoC

The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-21750
Windows 10 Version 1809 Windows
7.1
HIGH
EPSS
2.7%
2023 CWE-284 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-7174
aBitGone CommentSafe Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-28344
Software Genérico Web Windows
7.1
HIGH
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. Attackers are able to view screenshots of student desktops without their consent. These screenshots may potentially contain sensitive/personal data. Attackers can also rapidly submit falsified images, hiding the actual contents of student desktops from the Teacher Console.

CVE-2023-6279
Woostify Sites Library Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update arbitrary blog options and set them to 'activated' which could lead to DoS when using a specific option name

CVE-2023-0191
vGPU software (guest driver - Windows), vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
7.1
HIGH
EPSS
0.1%
2023 CWE-119 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access may lead to denial of service or data tampering.

CVE-2023-53944
EasyPHP Webserver Web Windows
7.1
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.