11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-1310
WooCommerce Web Windows
4.9
MEDIUM
EPSS
0.6%
2024 1 PoC

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

CVE-2022-4108
Wholesale Market for WooCommerce Web Windows
4.9
MEDIUM
EPSS
0.6%
2022 1 PoC

The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not be able to (for example in multisite)

CVE-2022-2926
Download Manager Web Windows
4.9
MEDIUM
EPSS
2.7%
2022 CWE-22 1 PoC

The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

CVE-2022-4155
Contest Gallery Web Database Windows
4.9
MEDIUM
EPSS
1.3%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVE-2023-1427
Photo Gallery by 10Web Web Windows
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.

CVE-2024-10708
System Dashboard Web Windows ⚡ nuclei
4.9
MEDIUM
EPSS
8.5%
2024 1 PoC

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

CVE-2023-3721
WP-EMail Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4198
WP Social Sharing Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2020-7275
McAfee Endpoint Security (ENS) Windows
4.8
MEDIUM
EPSS
0.1%
2020 CWE-428 1 PoC

Accessing, modifying or executing executable files vulnerability in the uninstaller in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to execute arbitrary code via a carefully crafted input file.

CVE-2022-40672
CPO Shortcodes (WordPress plugin) Web Windows
4.8
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress.

CVE-2022-3836
Seed Social Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-4858
Simple Table Manager Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Table Manager WordPress plugin through 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4112
Quizlord Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Quizlord WordPress plugin through 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-3897
SureMDM Onpremise Windows
4.8
MEDIUM
EPSS
1.3%
2023 CWE-203 2 PoCs

Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. This issue affects SureMDM On-premise: 6.31 and below version

CVE-2020-7308
McAfee Endpoint Security (ENS) for WIndows Windows
4.8
MEDIUM
EPSS
0.1%
2020 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an attacker to intercept requests and send their own responses.

CVE-2020-7333
Endpoint Security for Windows Networking Windows
4.8
MEDIUM
EPSS
0.4%
2020 CWE-79 1 PoC

Cross site scripting vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows administrators to inject arbitrary web script or HTML via the configuration wizard.

CVE-2023-3170
tagDiv Composer Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0548
Namaste! LMS Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3441
Rock Convert Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-3248
All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)