11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2017-8543
🔥 KEV Microsoft Windows Windows
9.8
CRITICAL
EPSS
85.1%
2017 1 PoC

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

CVE-2024-6809
Simple Video Directory Web Database Windows
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2021-34646
Booster for WooCommcerce Web Windows
9.8
CRITICAL
EPSS
22.5%
2021 CWE-290 2 PoCs

Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file. This allows attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Email Verification module to be act

CVE-2009-2494
Software Genérico Windows
9.8
CRITICAL
EPSS
63.3%
2009 1 PoC

The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."

CVE-2009-2512
Software Genérico Web Windows
9.8
CRITICAL
EPSS
37.8%
2009 1 PoC

The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka "Web Services on Devices API Memory Corruption Vulnerability."

CVE-2024-6460
Grow by Tradedoubler Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2024 3 PoCs

The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-37393
Software Genérico Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 3 PoCs

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.

CVE-2008-4835
Software Genérico Windows
9.8
CRITICAL
EPSS
66.7%
2008 1 PoC

SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."

CVE-2024-10589
Leopard - WordPress Offload Media Web Windows
9.8
CRITICAL
EPSS
0.4%
2024 CWE-862 1 PoC

The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the import_settings() function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVE-2024-6330
GEO my WP Web Windows
9.8
CRITICAL
EPSS
43.5%
2024 2 PoCs

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

CVE-2024-7094
JS Help Desk – AI-Powered Support & Ticketing System Web Windows
9.8
CRITICAL
EPSS
72.0%
2024 CWE-94 1 PoC

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully patched in 2.8.7 when the missing authorization and

CVE-2023-3211
WordPress Database Administrator Web Database Windows
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-8277
WooCommerce Photo Reviews Premium Web Windows
9.8
CRITICAL
EPSS
52.1%
2024 CWE-288 1 PoC

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly verifying the user's identity. This makes it possible for unauthenticated attackers to log in as user that has dismissed an admin notice in the past 30 days, which is often an administrator. Alternatively, a user can log in as any user with any transient that has a valid user_id as the value, though it would be more difficult t

CVE-2024-4898
InstaWP Connect – 1-click WP Staging & Migration Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.1%
2024 CWE-862 3 PoCs

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options and create administrator accounts.

CVE-2022-34487
Shortcode Addons (WordPress plugin) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
42.5%
2022 CWE-264 0 PoCs

Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.

CVE-2022-4445
FL3R FeelBox Web Database Windows
9.8
CRITICAL
EPSS
4.7%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-3481
WooCommerce Dropshipping Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
48.0%
2022 1 PoC

The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection

CVE-2022-4063
InPost Gallery Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.0%
2022 1 PoC

The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

CVE-2022-3634
Contact Form 7 Database Addon Web Windows
9.8
CRITICAL
EPSS
1.0%
2022 1 PoC

The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection