11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-2300
Contact Form Builder by vcita Web Windows
6.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 4.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as contributors and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2019-11208
TIBCO API Exchange Gateway Web Windows
6.4
MEDIUM
EPSS
0.2%
2019 1 PoC

The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint, when the implementation uses multiple scopes. This issue affects: TIBCO Software Inc.'s TIBCO API Exchange Gateway version 2.3.1 and prior versions, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric version 2.3.1 and prior versions.

CVE-2025-12628
WP 2FA Web Windows
6.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them

CVE-2024-2234
Himer Web Windows
6.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2020-26299
ftp-srv Windows
6.3
MEDIUM
EPSS
1.0%
2020 CWE-22 1 PoC

ftp-srv is an open-source FTP server designed to be simple yet configurable. In ftp-srv before version 4.4.0 there is a path-traversal vulnerability. Clients of FTP servers utilizing ftp-srv hosted on Windows machines can escape the FTP user's defined root folder using the expected FTP commands, for example, CWD and UPDR. When windows separators exist within the path (`\`), `path.resolve` leaves the upper pointers intact and allows the user to move beyond the root folder defined for that user. We did not take that into account when creating the path resolve function. The issue is patched in ve

CVE-2023-27867
Db2 for Linux, UNIX and Windows Windows
6.3
MEDIUM
EPSS
0.2%
2023 CWE-94 1 PoC

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249514.

CVE-2019-0986
Windows 10 Version 1703 Windows
6.3
MEDIUM
EPSS
2.3%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete files or folders of their choosing. The security update addresses the vulnerability by correcting how the Windows User Profile Service handles symlinks.

CVE-2024-3188
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2025-8182
AC18 Windows
6.3
MEDIUM
EPSS
0.1%
2025 CWE-521 1 PoC

A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

CVE-2023-27868
Db2 for Linux, UNIX and Windows Windows
6.3
MEDIUM
EPSS
0.2%
2023 CWE-94 1 PoC

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request using the named pluginClassName class, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249516.

CVE-2024-4655
Ultimate Blocks Web Windows
6.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2025-11212
Chrome Windows
6.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-3745
WP Lightbox 2 Web Windows
6.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.

CVE-2023-2971
Typora Windows
6.3
MEDIUM
EPSS
0.1%
2023 CWE-22 1 PoC

Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.

CVE-2024-36071
Software Genérico Windows
6.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This occurs because of an Untrusted Search Path.

CVE-2024-6751
Social Auto Poster Web Windows
6.3
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.

CVE-2022-4974
YASR – Yet Another Star Rating Plugin for WordPress Web Windows
6.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.

CVE-2023-27869
Db2 for Linux, UNIX and Windows Windows
6.3
MEDIUM
EPSS
0.2%
2023 CWE-94 1 PoC

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249517.

CVE-2024-2235
Himer Web Windows
6.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, including those they don't have access to via a CSRF attack

CVE-2022-38730
Software Genérico DevOps Web Windows
6.3
MEDIUM
EPSS
0.0%
2022 1 PoC

Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in ..\dataRoot\network\files\local-kv.db because of a TOCTOU race condition.