1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-6620
POST SMTP Mailer Web Database Windows
7.2
HIGH
EPSS
3.4%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-7027
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Web Windows
7.2
HIGH
EPSS
0.8%
2023 CWE-79 1 PoC

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-24955
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows
7.2
HIGH
EPSS
91.6%
2023 CWE-94 2 PoCs

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2023-23550
UR32L Windows
7.2
HIGH
EPSS
0.3%
2023 CWE-77 2 PoCs

An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-0291
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Web Windows
7.2
HIGH
EPSS
0.1%
2023 CWE-862 1 PoC

The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.

CVE-2023-0191
vGPU software (guest driver - Windows), vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
7.1
HIGH
EPSS
0.1%
2023 CWE-119 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access may lead to denial of service or data tampering.

CVE-2023-28344
Software Genérico Web Windows
7.1
HIGH
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. Attackers are able to view screenshots of student desktops without their consent. These screenshots may potentially contain sensitive/personal data. Attackers can also rapidly submit falsified images, hiding the actual contents of student desktops from the Teacher Console.

CVE-2023-7197
Marketing Twitter Bot Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-6279
Woostify Sites Library Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update arbitrary blog options and set them to 'activated' which could lead to DoS when using a specific option name

CVE-2023-21750
Windows 10 Version 1809 Windows
7.1
HIGH
EPSS
2.7%
2023 CWE-284 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-21752
Windows 10 Version 22H2 Windows
7.1
HIGH
EPSS
33.0%
2023 CWE-284 2 PoCs

Windows Backup Service Elevation of Privilege Vulnerability

CVE-2023-0181
vGPU software (guest driver - Windows), vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
7.1
HIGH
EPSS
0.0%
2023 CWE-280 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

CVE-2023-7174
aBitGone CommentSafe Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-53944
EasyPHP Webserver Web Windows
7.1
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.

CVE-2023-28218
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
30.4%
2023 CWE-122 1 PoC

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2023-28229
🔥 KEV Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
8.6%
2023 CWE-591 1 PoC

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2023-36403
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
0.2%
2023 CWE-591 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36427
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
9.9%
2023 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2023-21739
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
0.4%
2023 CWE-591 1 PoC

Windows Bluetooth Driver Elevation of Privilege Vulnerability

CVE-2023-5097
Workforce Access Windows
7.0
HIGH
EPSS
0.1%
2023 CWE-22 1 PoC

Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.