11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-9191
Houzez Web Windows
6.3
MEDIUM
EPSS
0.2%
2025 CWE-502 1 PoC

The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to pe

CVE-2015-10087
Theme DesignFolio Plus Web Windows
6.3
MEDIUM
EPSS
0.6%
2015 CWE-434 3 PoCs

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 53f6ae62878076f99718e5feb589928e83c879a9. It is recommended to apply a patch to fix this issue. The identifier VDB-221809 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no

CVE-2026-21525
🔥 KEV Windows 10 Version 1607 Windows
6.2
MEDIUM
EPSS
9.4%
2026 CWE-476 2 PoCs

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

CVE-2018-6660
ePolicy Orchestrator (ePO) Windows
6.2
MEDIUM
EPSS
1.0%
2018 1 PoC

Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path when exporting a particular XML file.

CVE-2021-1093
NVIDIA GPU Display Driver Windows
6.2
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash.

CVE-2024-12275
Canvasflow for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-0514
Membership Database Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
12.5%
2023 1 PoC

The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1835
Ninja Forms Contact Form Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2023 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2022-4295
Show All Comments Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2022 1 PoC

The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

CVE-2024-13115
WP Projects Portfolio with Client Testimonials Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-7230
illi Link Party! Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks.

CVE-2024-13431
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2024 CWE-79 1 PoC

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-0420
MapPress Maps for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

CVE-2023-6389
WordPress Toolbar Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
52.5%
2023 1 PoC

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-12282
WordPress连接微博 Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-0876
WP Meta SEO Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2023 1 PoC

The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.

CVE-2024-5079
wp-eMember Web Windows
6.1
MEDIUM
EPSS
2.0%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2024-6667
KBucket: Your Curated Content in WordPress Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin.

CVE-2023-6050
Estatik Real Estate Plugin Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-6627
WP Go Maps (formerly WP Google Maps) Web Windows
6.1
MEDIUM
EPSS
1.2%
2023 2 PoCs

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.