11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-51778
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

CVE-2024-31211
wordpress-develop Web Windows
5.5
MEDIUM
EPSS
39.7%
2024 CWE-502 1 PoC

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.

CVE-2024-3048
Bannerlid Web Windows
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

CVE-2024-0092
GPU display driver, vGPU software, and Cloud Gaming Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2024 CWE-703 1 PoC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.

CVE-2022-46692
iCloud for Windows Cloud Windows
5.5
MEDIUM
EPSS
0.0%
2022 5 PoCs

A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.

CVE-2022-24483
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
5.9%
2022 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2022-21877
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
15.0%
2022 1 PoC

Storage Spaces Controller Information Disclosure Vulnerability

CVE-2022-34681
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a display-related data structure may lead to denial of service.

CVE-2022-2473
WP-UserOnline Web Windows
5.5
MEDIUM
EPSS
1.0%
2022 CWE-79 3 PoCs

The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The only affects multi-site installations and installations where unfiltered_html is disabled.

CVE-2022-34683
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 2 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service.

CVE-2023-21899
VM VirtualBox Database Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. Note: Applies to VirtualBox VMs running Windows 7 and later. CVSS 3.1 Base Score 5.5 (Availabi

CVE-2020-11049
FreeRDP Windows
5.5
MEDIUM
EPSS
0.2%
2020 CWE-125 1 PoC

In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0.

CVE-2024-22104
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

CVE-2024-3824
Base64 Encoder/Decoder Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

CVE-2023-21776
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
1.9%
2023 CWE-125 2 PoCs

Windows Kernel Information Disclosure Vulnerability

CVE-2020-11047
FreeRDP Windows
5.5
MEDIUM
EPSS
0.1%
2020 CWE-125 1 PoC

In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.

CVE-2020-3347
Cisco WebEx Meetings Server Networking Windows
5.5
MEDIUM
EPSS
0.1%
2020 CWE-200 1 PoC

A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. The vulnerability is due to unsafe usage of shared memory that is used by the affected software. An attacker with permissions to view system memory could exploit this vulnerability by running an application on the local system that is designed to read shared memory. A successful exploit could allow the attacker to retrieve sensitive information from the shared memory, including usernames, meeting information, or authenticati

CVE-2024-4759
Mime Types Extended Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2025-10874
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Web Windows
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

CVE-2024-22105
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.