11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-3749
SP Project & Document Manager Web Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user

CVE-2024-0559
Enhanced Text Widget Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2025-12685
WPBookit Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.

CVE-2022-3880
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2024-1316
Event Tickets and Registration Web Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).

CVE-2024-5570
Simple Photoswipe Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them

CVE-2024-6855
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2022-2762
AdminPad Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack

CVE-2022-23253
Windows 10 Version 1809 Windows
6.5
MEDIUM
EPSS
30.2%
2022 1 PoC

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

CVE-2024-3748
SP Project & Document Manager Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user

CVE-2024-5072
Server Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.

CVE-2024-7688
AZIndex Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack

CVE-2022-4151
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2024-12558
WP BASE Booking of Appointments, Services and Events Web Windows
6.5
MEDIUM
EPSS
30.8%
2024 CWE-862 2 PoCs

The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose sensitive information from the database, such as the hashed administrator password.

CVE-2022-4548
Optimize images ALT Text (alt tag) & names for SEO using AI Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2024-6133
wp-cart-for-digital-products Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-43408
Duplicate Post WordPress Plugin Web Database Windows
6.5
MEDIUM
EPSS
30.6%
2021 CWE-89 1 PoC

The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrat

CVE-2024-0078
GPU Display driver, vGPU driver, Cloud Gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.

CVE-2024-1287
pmpro-member-directory Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

CVE-2024-6856
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack