11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-7263
Endpoint Security (ENS) for Window Windows
6.5
MEDIUM
EPSS
0.0%
2020 CWE-264 1 PoC

Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.

CVE-2024-7135
Tainacan Web Windows
6.5
MEDIUM
EPSS
48.0%
2024 CWE-862 2 PoCs

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2023-6048
Estatik Real Estate Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and lead to DoS when certain options are reset

CVE-2024-22532
Software Genérico Windows
6.5
MEDIUM
EPSS
5.1%
2024 1 PoC

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

CVE-2024-6025
Quiz and Survey Master (QSM) Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks

CVE-2022-47938
Software Genérico Windows
6.5
MEDIUM
EPSS
4.6%
2022 1 PoC

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-bounds read and OOPS for SMB2_TREE_CONNECT.

CVE-2023-1330
Redirection Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

CVE-2025-12685
WPBookit Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.

CVE-2023-0335
WP Shamsi Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.

CVE-2018-6687
McAfee GetSusp (GetSusp) Windows
6.5
MEDIUM
EPSS
0.1%
2018 1 PoC

Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp scan via while scanning a specifically crafted file . GetSusp is a free standalone McAfee tool that runs on several versions of Microsoft Windows.

CVE-2024-43451
🔥 KEV Windows Server 2025 Windows
6.5
MEDIUM
EPSS
90.3%
2024 CWE-73 1 PoC

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-55311
Software Genérico Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.

CVE-2023-3508
WooCommerce Pre-Orders Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks

CVE-2017-0022
🔥 KEV XML Core Services Windows
6.5
MEDIUM
EPSS
39.7%
2017 1 PoC

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."

CVE-2021-24085
Microsoft Exchange Server 2019 Cumulative Update 8 Windows
6.5
MEDIUM
EPSS
13.2%
2021 1 PoC

Microsoft Exchange Server Spoofing Vulnerability

CVE-2023-51071
Software Genérico Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.

CVE-2023-0501
WP Insurance Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2020-36721
Brilliance Web Windows
6.5
MEDIUM
EPSS
0.2%
2020 CWE-284 1 PoC

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.

CVE-2021-41349
Microsoft Exchange Server 2013 Cumulative Update 23 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
91.1%
2021 2 PoCs

Microsoft Exchange Server Spoofing Vulnerability

CVE-2023-34367
Software Genérico Windows
6.5
MEDIUM
EPSS
1.2%
2023 2 PoCs

Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor considers this a low severity issue.