11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-40586
FortiClientWindows Networking Windows
6.3
MEDIUM
EPSS
0.0%
2024 CWE-284 1 PoC

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.

CVE-2025-10567
FunnelKit Web Windows
6.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.

CVE-2025-8182
AC18 Windows
6.3
MEDIUM
EPSS
0.1%
2025 CWE-521 1 PoC

A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

CVE-2019-3588
McAfee VirusScan Enterprise (VSE) Windows
6.3
MEDIUM
EPSS
0.0%
2019 CWE-269 1 PoC

Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked.

CVE-2024-0427
ARForms - Premium WordPress Form Builder Plugin Web Windows
6.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controlled input when it is reflected in some of its AJAX actions.

CVE-2020-36833
Indeed Membership Pro Web Windows
6.3
MEDIUM
EPSS
0.1%
2020 CWE-862 1 PoC

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - 8.6. This makes it possible for authenticated attacker, with minimal permission, such as a subscriber, to perform a variety of actions such as modifying settings and viewing sensitive data.

CVE-2024-0085
vGPU software and Cloud Gaming Cloud Windows
6.3
MEDIUM
EPSS
0.1%
2024 CWE-266 1 PoC

NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.

CVE-2020-9291
Fortinet FortiClient for Windows Networking Windows
6.3
MEDIUM
EPSS
0.1%
2020 1 PoC

An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack.

CVE-2022-3734
Redis Database Windows
6.3
MEDIUM
EPSS
0.5%
2022 CWE-426 1 PoC

A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier of this vulnerability is VDB-212416. NOTE: The official Redis release is not affected. This issue might affect an unofficial fork or port on Windows only.

CVE-2025-9191
Houzez Web Windows
6.3
MEDIUM
EPSS
0.2%
2025 CWE-502 1 PoC

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to pe

CVE-2024-4530
Business Card Web Windows
6.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks

CVE-2024-2040
Himer Web Windows
6.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users join private groups via a CSRF attack

CVE-2024-2603
Salon booking system Web Windows
6.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2762
FooGallery Web Windows
6.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back in the page, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVE-2024-2233
Himer Web Windows
6.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group invitations or leaving a group

CVE-2025-6027
Ace User Management Web Windows
6.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, allowing any authenticated users, such as subscriber to reset the password of arbitrary accounts, including administrators.

CVE-2024-8243
WordPress/Plugin Upgrade Time Out Plugin Web Windows
6.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-0905
Fancy Product Designer Web Windows
6.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users

CVE-2023-6008
UserPro - Community and User Profile WordPress Plugin Web Windows
6.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

CVE-2019-19984
Software Genérico Web Windows
6.3
MEDIUM
EPSS
0.2%
2019 1 PoC

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.