11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-17113
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
1.3%
2020 1 PoC

Windows Camera Codec Information Disclosure Vulnerability

CVE-2023-7229
illi Link Party! Web Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2022-30155
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2022 1 PoC

Windows Kernel Denial of Service Vulnerability

CVE-2024-7061
Okta Verify for Windows Windows
5.5
MEDIUM
EPSS
0.1%
2024 CWE-22 1 PoC

Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.

CVE-2023-4823
WP Meta and Date Remover Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.

CVE-2023-0177
Social Like Box and Page by WpDevArt Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-6082
chartjs Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-0171
jQuery T(-) Countdown Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-1626
Qi Blocks Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-12905
Chrome Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-11154
IDonate Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVE-2023-3575
Quiz And Survey Master Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0267
Ultimate Carousel For WPBakery Page Builder Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-2413
Slide Anything Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even when the unfiltered_html capability is disabled.

CVE-2023-7086
SVG Uploads Support Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-5651
WP Hotel Booking Web Windows
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

CVE-2023-1126
WP FEvents Book Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks

CVE-2023-0292
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Web Windows
5.4
MEDIUM
EPSS
0.5%
2023 CWE-352 1 PoC

The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0175
Responsive Clients Logo Gallery Plugin for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0146
Naver Map Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.