11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-6768
Windows 10 Windows
6.8
MEDIUM
EPSS
19.3%
2024 CWE-1284 4 PoCs

A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to the KeBugCheckEx function.

CVE-2024-37085
🔥 KEV VMware ESXi Web Windows
6.8
MEDIUM
EPSS
75.1%
2024 4 PoCs

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

CVE-2022-4512
Better Font Awesome Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-12502
attention-bar Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users such as administrator to perform SQL injection attacks

CVE-2025-3742
Responsive Lightbox & Gallery Web Windows
6.8
MEDIUM
EPSS
0.3%
2025 1 PoC

The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5077
wp-eMember Web Windows
6.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2025-14973
Recipe Card Blocks Lite Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks.

CVE-2024-2761
Genesis Blocks Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.

CVE-2025-2055
MapPress Maps for WordPress Web Windows
6.8
MEDIUM
EPSS
0.5%
2025 1 PoC

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2026-1753
Gutena Forms Web Windows
6.8
MEDIUM
EPSS
0.0%
2026 1 PoC

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

CVE-2024-6021
Donation Block For PayPal Web Windows
6.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Donation Block For PayPal WordPress plugin through 2.1.0 does not sanitise and escape form submissions, leading to a stored cross-site scripting vulnerability

CVE-2024-3669
Web Directory Free Web Windows
6.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2022-47632
Software Genérico Windows
6.8
MEDIUM
EPSS
0.1%
2022 5 PoCs

Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can place malicious DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the service is installed and if they deny write access for the SYSTEM user. Although the service will not start if the malicious DLLs are unsigned, it suffices to use self-signed DLLs. The validity of the DLL signatures is not checked. As a result, local Windows users can abuse the Razer driver installer to obtain administrativ

CVE-2023-0075
Amazon JS Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-8743
File Manager Web Windows
6.8
MEDIUM
EPSS
42.9%
2024 CWE-434 1 PoC

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.

CVE-2024-3710
Image Photo Gallery Final Tiles Grid Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVE-2024-10709
YaDisk Files Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4761
Post Views Count (Support caching plugins!) Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2020-1034
Windows 10 Version 1803 Windows
6.8
MEDIUM
EPSS
17.0%
2020 3 PoCs

<p>An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.</p> <p>The security update addresses the vulnerability by ensuring the Windows Kernel properly handles objects in memory.</p>

CVE-2024-5284
wp-affiliate-platform Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack