1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-1207
HTTP Headers Web Database Windows
7.2
HIGH
EPSS
0.3%
2023 1 PoC

This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.

CVE-2023-23550
UR32L Windows
7.2
HIGH
EPSS
0.3%
2023 CWE-77 2 PoCs

An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-4238
Prevent files / folders access Web Windows
7.2
HIGH
EPSS
24.7%
2023 2 PoCs

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

CVE-2023-7082
Import any XML or CSV File to WordPress Web Windows
7.2
HIGH
EPSS
3.5%
2023 1 PoC

The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessible directory without sufficiently validating the extracted file type. This may allows high privilege users such as administrator to upload an executable file type leading to remote code execution.

CVE-2023-0278
GeoDirectory Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-6222
Quttera Web Malware Scanner Web Windows
7.2
HIGH
EPSS
0.4%
2023 2 PoCs

IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks

CVE-2023-3664
FileOrganizer Web Windows
7.2
HIGH
EPSS
0.4%
2023 1 PoC

The FileOrganizer WordPress plugin through 1.0.2 does not restrict functionality on multisite instances, allowing site admins to gain full control over the server.

CVE-2023-0277
WC Fields Factory Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-0924
ZYREX POPUP Web Windows
7.2
HIGH
EPSS
1.0%
2023 1 PoC

The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install.

CVE-2023-24595
UR32L Windows
7.2
HIGH
EPSS
0.3%
2023 CWE-78 2 PoCs

An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted series of network requests can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-0575
YugabyteDB Web Windows
7.2
HIGH
EPSS
0.5%
2023 CWE-642 1 PoC

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.0.0

CVE-2023-0279
Media Library Assistant Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-4691
WordPress Online Booking and Scheduling Plugin Web Database Windows
7.2
HIGH
EPSS
0.2%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-2655
Contact Form by WD Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-0487
All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-22883
Zoom Client for Meetings for IT Admin Windows installers Windows
7.2
HIGH
EPSS
0.1%
2023 CWE-367 1 PoC

Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to the SYSTEM user.

CVE-2023-4314
wpDataTables Web Windows
7.2
HIGH
EPSS
5.1%
2023 1 PoC

The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deserializing the data. This allows admins to deserialize arbitrary data which may lead to remote code execution if a suitable gadget chain is present on the server. This is impactful in environments where admin users should not be allowed to execute arbitrary code, such as multisite.

CVE-2023-3155
WordPress Gallery Plugin Web Windows
7.2
HIGH
EPSS
0.4%
2023 1 PoC

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

CVE-2023-4797
Newsletters Web Database Windows
7.2
HIGH
EPSS
0.6%
2023 1 PoC

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

CVE-2023-1347
Customizer Export/Import Web Windows
7.2
HIGH
EPSS
5.9%
2023 1 PoC

The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present