1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13681
Uncode Web Windows
7.5
HIGH
EPSS
0.3%
2024 CWE-20 1 PoC

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to read arbitrary files on the server.

CVE-2024-11423
Gift Cards for WooCommerce Pro Web Windows
7.5
HIGH
EPSS
20.7%
2024 CWE-862 1 PoC

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints such as /wp-json/gifting/recharge-giftcard in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to recharge a gift card balance, without making a payment along with reducing gift card balances wi

CVE-2024-12172
WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses Web Windows
7.5
HIGH
EPSS
11.2%
2024 CWE-862 1 PoC

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpc_update_user_meta_option() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary user's metadata which can be levereged to block an administrator from accessing their site when wp_capabilities is set to 0.

CVE-2024-12157
Popup – MailChimp, GetResponse and ActiveCampaign Intergrations Web Database Windows
7.5
HIGH
EPSS
10.2%
2024 CWE-89 1 PoC

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'upc_delete_db_record' AJAX action in all versions up to, and including, 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-11728
KiviCare – Clinic & Patient Management System (EHR) Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
65.9%
2024 CWE-89 1 PoC

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-3475
Sticky Buttons Web Windows
7.5
HIGH
EPSS
0.1%
2024 1 PoC

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

CVE-2024-9935
PDF Generator for WordPress Elementor Web Windows ⚡ nuclei
7.5
HIGH
EPSS
93.8%
2024 CWE-22 3 PoCs

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-24569 may be a duplicate of this issue.

CVE-2024-13925
Klarna Checkout for WooCommerce Web Windows
7.5
HIGH
EPSS
0.6%
2024 1 PoC

The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.

CVE-2024-38257
Windows 10 Version 1809 Web Windows
7.5
HIGH
EPSS
4.3%
2024 CWE-908 1 PoC

Microsoft AllJoyn API Information Disclosure Vulnerability

CVE-2024-5882
Ultimate Classified Listings Web Windows
7.5
HIGH
EPSS
2.3%
2024 1 PoC

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

CVE-2024-6492
Remote Desktop Manager Windows
7.4
HIGH
EPSS
0.6%
2024 1 PoC

Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.

CVE-2024-31954
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (An attacker must already have user privileges)

CVE-2024-20696
Windows 10 Version 1809 Windows
7.3
HIGH
EPSS
7.2%
2024 CWE-122 1 PoC

Windows libarchive Remote Code Execution Vulnerability

CVE-2024-9061
WP Popup Builder – Popup Forms and Marketing Lead Generation Web Windows ⚡ nuclei
7.3
HIGH
EPSS
89.0%
2024 CWE-94 1 PoC

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. How

CVE-2024-5102
Antivirus Windows
7.3
HIGH
EPSS
0.1%
2024 CWE-1284 1 PoC

A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\SYSTEM. A low-privileged user can make a pseudo-symlink and a junction folder and point to a file on the system. This can provide a low-privileged user an Elevation of Privilege to win a race-condition which will re-create the s

CVE-2024-35061
Software Genérico Windows
7.3
HIGH
EPSS
1.4%
2024 1 PoC

NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.

CVE-2024-10958
WP Photo Album Plus Web Windows
7.3
HIGH
EPSS
55.7%
2024 CWE-94 1 PoC

The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2024-23769
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

CVE-2024-40445
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 2 PoCs

A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.

CVE-2024-11740
Download Manager Web Windows ⚡ nuclei
7.3
HIGH
EPSS
11.8%
2024 CWE-94 0 PoCs

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.