11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-34424
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Windows
5.3
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI

CVE-2024-11396
Event Monster – Manager & Ticket Booking Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
54.2%
2024 CWE-359 1 PoC

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.

CVE-2024-1526
Hubbub Lite Web Windows
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.

CVE-2019-1040
Windows 10 Version 1703 Windows
5.3
MEDIUM
EPSS
89.8%
2019 5 PoCs

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the NTLM exchange. The attacker could then modify flags of the NTLM packet without invalidating the signature. The update addresses the vulnerability by hardening NTLM MIC protection on the server-side.

CVE-2023-6592
FastDup Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
4.4%
2023 2 PoCs

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

CVE-2024-0624
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions Web Windows
5.3
MEDIUM
EPSS
4.0%
2024 CWE-352 1 PoC

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible for unauthenticated attackers to update the order of levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2022-1613
Restricted Site Access Web Windows
5.3
MEDIUM
EPSS
0.2%
2022 CWE-639 1 PoC

The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.

CVE-2022-4340
BookingPress Web Windows
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.

CVE-2022-4057
Autoptimize Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
45.4%
2022 1 PoC

The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.

CVE-2019-3654
Client Proxy (MCP) Windows
5.3
MEDIUM
EPSS
0.1%
2019 1 PoC

Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of time via generating an authorization key on the client which should only be generated by the network administrator.

CVE-2019-3883
389-ds-base Windows
5.3
MEDIUM
EPSS
0.9%
2019 CWE-772 1 PoC

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVE-2024-0593
Simple Job Board Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
6.7%
2024 CWE-862 0 PoCs

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password protected or private and contain sensitive information.

CVE-2024-5333
The Events Calendar Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
11.0%
2024 1 PoC

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

CVE-2024-6704
Comments – wpDiscuz Web Windows
5.3
MEDIUM
EPSS
8.4%
2024 CWE-79 1 PoC

The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled.

CVE-2019-9510
Windows 10 or newer system using RDP Windows
5.3
MEDIUM
EPSS
1.0%
2019 CWE-288 1 PoC

A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network anomaly trigger a temporary RDP disconnect, Automatic Reconnection of the RDP session will be restored to an unlocked state, regardless of how the remote system was left. By interrupting network connectivity of a system, an attacker with access to a system being used as a Windows RDP client can gain access to a connected remote system, regardless of whether

CVE-2024-0868
coreActivity: Activity Logging plugin for WordPress Web Windows
5.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value

CVE-2019-3888
undertow Web Windows
5.3
MEDIUM
EPSS
0.6%
2019 CWE-532 1 PoC

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

CVE-2024-0236
EventON Web Windows
5.3
MEDIUM
EPSS
0.5%
2024 1 PoC

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)

CVE-2024-1219
Easy Social Feed Web Windows
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Easy Social Feed WordPress plugin before 6.5.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVE-2024-0237
EventON Premium Web Windows
5.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual events settings, such as meeting URL, moderator, access details etc