1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-1095
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.

CVE-2021-23886
McAfee Data Loss Prevention (DLP) Endpoint for Windows Windows
5.5
MEDIUM
EPSS
0.0%
2021 CWE-755 2 PoCs

Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory.

CVE-2021-31955
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.1%
2021 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2021-24366
Admin Columns Web Windows
5.4
MEDIUM
EPSS
0.4%
2021 1 PoC

The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-24559
Qyrr Web Windows
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJAX action, available to all authenticated users, only had a CSRF check in place, with the nonce available to users with a role as low as Contributor allowing any user with such role (and above) to set a malicious data-uri in arbitrary QR Code posts, leading to a Stored Cross-Site Scripting issue.

CVE-2021-4417
Forminator Forms – Contact Form, Payment Form & Custom Form Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13.4. This is due to missing or incorrect nonce validation on the listen_for_saving_export_schedule() function. This makes it possible for unauthenticated attackers to export form submissions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-26829
🔥 KEV Software Genérico Web Windows
5.4
MEDIUM
EPSS
7.6%
2021 2 PoCs

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

CVE-2021-24433
simple sort&search Web Windows
5.4
MEDIUM
EPSS
0.3%
2021 1 PoC

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor

CVE-2021-24567
Simple Post Web Windows
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.

CVE-2021-25059
Download Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.

CVE-2021-39327
BulletProof Security Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
90.9%
2021 CWE-200 2 PoCs

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

CVE-2021-34424
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Windows
5.3
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI

CVE-2021-38314
Gutenberg Template Library & Redux Framework Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
84.1%
2021 CWE-200 8 PoCs

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site’s `AU

CVE-2021-4227
ark-commenteditor Web Windows
5.3
MEDIUM
EPSS
0.2%
2021 1 PoC

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

CVE-2021-41160
FreeRDP Web Windows
5.3
MEDIUM
EPSS
0.1%
2021 CWE-787 1 PoC

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of bound rectangles to trigger out of bound writes. With `0` width or heigth the memory allocation will be `0` but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.

CVE-2021-31832
McAfee Data Loss Prevention (DLP) Endpoint for Windows Web Windows
5.2
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

Improper Neutralization of Input in the ePO administrator extension for McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a remote ePO DLP administrator to inject JavaScript code into the alert configuration text field. This JavaScript will be executed when an end user triggers a DLP policy on their machine.

CVE-2021-47957
Cookie Law Bar Web Windows
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Attackers can inject script payloads through the plugin settings page that execute in the browsers of all WordPress users viewing the site, enabling cookie theft and sensitive data exfiltration.

CVE-2021-1645
Windows Server version 20H2 DevOps Windows
5.0
MEDIUM
EPSS
34.2%
2021 2 PoCs

Windows Docker Information Disclosure Vulnerability

CVE-2021-31842
McAfee Endpoint Security (ENS) for WIndows Windows
5.0
MEDIUM
EPSS
0.0%
2021 CWE-776 1 PoC

XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process.

CVE-2021-28198
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.