1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-1119
Simple File List Web Windows ⚡ nuclei
7.5
HIGH
EPSS
82.3%
2022 CWE-22 3 PoCs

The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.

CVE-2022-47941
Software Genérico Windows
7.5
HIGH
EPSS
2.0%
2022 1 PoC

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.

CVE-2022-4140
Welcart e-Commerce Web Windows ⚡ nuclei
7.5
HIGH
EPSS
54.3%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server

CVE-2022-48483
Software Genérico Windows
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue exists because of an incomplete fix for CVE-2022-28005.

CVE-2022-41840
Welcart e-Commerce (WordPress plugin) Web Windows ⚡ nuclei
7.5
HIGH
EPSS
79.4%
2022 CWE-22 0 PoCs

Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

CVE-2022-4158
Contest Gallery Web Database Windows
7.5
HIGH
EPSS
1.3%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the site's database.

CVE-2022-1442
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor Web Windows ⚡ nuclei
7.5
HIGH
EPSS
74.9%
2022 CWE-862 1 PoC

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.

CVE-2022-3846
Workreap Web Windows
7.5
HIGH
EPSS
0.5%
2022 1 PoC

The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.

CVE-2022-3119
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Web Windows
7.5
HIGH
EPSS
0.2%
2022 CWE-287 1 PoC

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

CVE-2022-22737
Firefox ESR Windows
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVE-2022-4550
User Activity Web Windows
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing

CVE-2022-23831
AMD μProf Windows
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.

CVE-2022-32230
Windows 10 Version 20H2 Windows
7.5
HIGH
EPSS
28.9%
2022 CWE-476 1 PoC

Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the Windows kernel. For most systems, this attack requires authentication, except in the special case of Windows Domain Controllers, where unauthenticated users can always open named pipes as long as they can establish an SMB session. Typically, after the BSOD, the victim SMBv3 server will reboot.

CVE-2022-4106
Wholesale Market for WooCommerce Web Windows
7.5
HIGH
EPSS
1.2%
2022 1 PoC

The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVE-2022-2633
All-in-One Video Gallery Web Windows ⚡ nuclei
7.5
HIGH
EPSS
88.4%
2022 0 PoCs

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.

CVE-2022-3691
DeepL Pro API translation plugin Web Windows
7.5
HIGH
EPSS
1.1%
2022 1 PoC

The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.

CVE-2022-4156
Contest Gallery Web Database Windows
7.5
HIGH
EPSS
0.8%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQL query in ajax-functions-backend.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-0280
McAfee Total Protection for Windows Windows
7.5
HIGH
EPSS
0.2%
2022 CWE-367 1 PoC

A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being deleted and potentially cause denial of service. This attack exploits the way symlinks are created and how the product works with them.

CVE-2022-1467
AVEVA InTouch Access Anywhere Windows
7.4
HIGH
EPSS
0.3%
2022 CWE-668 1 PoC

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVE-2022-39421
VM VirtualBox Database Windows
7.3
HIGH
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows systems only. CVSS 3.1 Base Score 7.3 (Confidentiality, Integr