1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-29336
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
79.5%
2023 CWE-416 2 PoCs

Win32k Elevation of Privilege Vulnerability

CVE-2023-38154
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.2%
2023 CWE-122 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-21749
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.5%
2023 CWE-20 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-20178
Cisco Secure Client Networking Windows
7.8
HIGH
EPSS
27.7%
2023 CWE-276 3 PoCs

A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A succe

CVE-2023-36407
Windows Server 2022 Windows
7.8
HIGH
EPSS
15.2%
2023 CWE-20 2 PoCs

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2023-35841
WinFlash Driver Windows
7.8
HIGH
EPSS
0.2%
2023 CWE-732 1 PoC

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.

CVE-2023-21823
🔥 KEV Microsoft Office for Android Windows
7.8
HIGH
EPSS
5.0%
2023 CWE-190 1 PoC

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2023-39421
IRM Next Generation Web Windows
7.7
HIGH
EPSS
0.1%
2023 CWE-798 1 PoC

The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.

CVE-2023-0098
Simple URLs Web Database Windows
7.7
HIGH
EPSS
0.7%
2023 1 PoC

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

CVE-2023-28853
mastodon Windows
7.7
HIGH
EPSS
1.1%
2023 CWE-90 1 PoC

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, and 4.1.2.

CVE-2023-0262
WP Airbnb Review Slider Web Database Windows
7.7
HIGH
EPSS
0.5%
2023 1 PoC

The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-28603
Zoom VDI Windows Meeting Client Windows
7.7
HIGH
EPSS
0.0%
2023 CWE-73 1 PoC

Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.

CVE-2023-29050
OX App Suite Windows
7.6
HIGH
EPSS
0.1%
2023 CWE-90 1 PoC

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load on the directory server, leading to denial of service. Encoding has been added for user-provided fragments that are used when constructing the LDAP query. No publicly available exploits are known.

CVE-2023-5644
WP Mail Log Web Windows
7.6
HIGH
EPSS
0.1%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

CVE-2023-2180
KIWIZ Invoices Certification & PDF System Web Windows
7.5
HIGH
EPSS
0.6%
2023 1 PoC

The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)

CVE-2023-6421
Download Manager Web Windows ⚡ nuclei
7.5
HIGH
EPSS
80.6%
2023 2 PoCs

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

CVE-2023-1405
Formidable Forms Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVE-2023-0331
Correos Oficial Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.

CVE-2023-6113
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated attackers to download said backups later.

CVE-2023-32113
SAP GUI for Windows Windows
7.5
HIGH
EPSS
0.2%
2023 CWE-200 1 PoC

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.