1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4024
Registration Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

CVE-2022-2449
reSmush.it : the only free Image Optimizer & compress plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site.

CVE-2022-4888
Checkout Fields Manager Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts WordPress plugin before 1.0.2, Gift Registry for WooCommerce WordPress plugin through 1.0.1, Image Watermark for WooCommerce WordPress plugin before 1.0.1, Order Approval for WooCommerce WordPress plugin before 1.1.0, Order Tracking for WooCommerce WordPress plugin before 1.0.2, Price Ca

CVE-2022-3762
Booster for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.8%
2022 1 PoC

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the server even when they are not supposed to be able to (for example in multisite)

CVE-2022-3926
WP OAuth Server (OAuth Authentication) Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID

CVE-2022-3946
Welcart e-Commerce Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.

CVE-2022-3879
Car Dealer (Dealership) and Vehicle sales WordPress Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-3882
Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-3880
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-3677
Advanced Import : One Click Import for WordPress or Theme Demo Data Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks

CVE-2022-34678
vGPU software (guest driver) - Windows, Linux and vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud Windows
6.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a null-pointer dereference, which may lead to denial of service.

CVE-2022-4152
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.9%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-3247
Blog2Social: Social Media Auto Post & Scheduler Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 CWE-918 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks

CVE-2022-23253
Windows 10 Version 1809 Windows
6.5
MEDIUM
EPSS
30.2%
2022 1 PoC

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

CVE-2022-3883
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-4236
Welcart e-Commerce Web Windows
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscriber to read arbitrary files on the server.

CVE-2022-30312
Software Genérico Windows
6.5
MEDIUM
EPSS
0.0%
2022 1 PoC

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected components are characterized as: Inter-Controller (IC) protocol (57612/UDP). The potential impact is: Compromise of credentials. Several Trend Controls building automation controllers utilize the Inter-Controller (IC) protocol in for information exchange and automation purposes. This protocol offers authentication in the form of a 4-digit PIN in or

CVE-2022-4016
Booster for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete arbitrary custom roles via CSRF attacks

CVE-2022-3538
Webmaster Tools Verification Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins

CVE-2022-2762
AdminPad Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack