11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-26263
Software Genérico Windows
5.1
MEDIUM
EPSS
0.3%
2025 1 PoC

GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.

CVE-2023-54358
WordPress adivaha Travel Plugin Web Windows
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.

CVE-2024-0677
Pz-LinkCard Web Windows
5.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.

CVE-2024-22318
i Access Client Solutions Windows
5.1
MEDIUM
EPSS
0.2%
2024 CWE-327 2 PoCs

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.

CVE-2019-25297
Poll, Survey & Quiz Maker Plugin by Opinion Stage Web Windows
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 3 PoCs

Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.

CVE-2019-25315
WP Server Log Viewer Web Windows
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface.

CVE-2020-37233
Buddypress Web Windows
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onload that execute when administrators or privileged users preview or view the affected page content, enabling session hijacking and persistent phishing attacks.

CVE-2022-50959
Contact Form Builder Web Windows
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.

CVE-2022-50949
Videos sync PDF Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus event handlers through the plugin options panel to execute arbitrary JavaScript when administrators view or edit video settings.

CVE-2021-47957
Cookie Law Bar Web Windows
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Attackers can inject script payloads through the plugin settings page that execute in the browsers of all WordPress users viewing the site, enabling cookie theft and sensitive data exfiltration.

CVE-2022-50945
real-time web stats Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress 3dady real-time web stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin options panel to execute arbitrary code when the page is viewed.

CVE-2022-50960
International Sms For Contact Form Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress International Sms For Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers.

CVE-2022-50958
Jetpack Web Windows
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.

CVE-2022-50797
Stripe Green Downloads Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module manipulation.

CVE-2024-3977
WordPress Jitsi Shortcode Web Windows
5.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2025-32103
CrushFTP Windows
5.0
MEDIUM
EPSS
1.6%
2025 CWE-40 2 PoCs

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.

CVE-2017-4028
McAfee Anti-Virus Plus (AVP) Windows
5.0
MEDIUM
EPSS
0.1%
2017 1 PoC

Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.

CVE-2021-1645
Windows Server version 20H2 DevOps Windows
5.0
MEDIUM
EPSS
34.2%
2021 2 PoCs

Windows Docker Information Disclosure Vulnerability

CVE-2024-4529
Business Card Web Windows
5.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks

CVE-2021-31842
McAfee Endpoint Security (ENS) for WIndows Windows
5.0
MEDIUM
EPSS
0.0%
2021 CWE-776 1 PoC

XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process.