11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-2375
WPQA Builder Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-2118
Social Media Share Buttons & Social Sharing Icons Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5604
Bug Library Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3113
FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection WordPress plugin before 2.12.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3590
WordPress Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
90.8%
2022 4 PoCs

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVE-2023-39209
Zoom Desktop Client for Windows Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-449 1 PoC

Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.

CVE-2024-3472
Modal Window Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-4752
EventON Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6243
HTML Forms Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

CVE-2024-10105
Job Postings Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6487
Inline Related Posts Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2025-6200
GeoDirectory Web Windows
5.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-10104
Jobs for WordPress Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2025-3201
Contact Form builder with drag & drop for WordPress Web Windows
5.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.

CVE-2024-9836
RSS Feed Widget Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2021-25736
Kubernetes DevOps Windows
5.8
MEDIUM
EPSS
0.1%
2021 1 PoC

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the “status.loadBalancer.ingress[].ip” field are unaffected.

CVE-2019-16780
WordPress Web Windows
5.8
MEDIUM
EPSS
3.6%
2019 CWE-79 2 PoCs

WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled.

CVE-2020-2558
Solaris Operating System Database Windows
5.8
MEDIUM
EPSS
1.5%
2020 2 PoCs

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.0 Base Score 5.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N

CVE-2019-16781
WordPress Web Windows
5.8
MEDIUM
EPSS
3.5%
2019 CWE-79 2 PoCs

In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.

CVE-2019-19985
Software Genérico Web Windows ⚡ nuclei
5.8
MEDIUM
EPSS
79.6%
2019 2 PoCs

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.