555 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-16860
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2019 2 PoCs

Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could create or modify a dynamic-link library (DLL). The Code42 service could then load it at runtime, and potentially execute arbitrary code at an elevated privilege on the local machine.

CVE-2019-12517
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality available via the /wp-admin/admin-ajax.php endpoint allows unauthenticated users to submit quiz solutions/answers, which are stored in the database and later shown in the WordPress backend for all users with at least Subscriber rights. Because the plugin does not properly validate and sanitize this data, a malicious payload in either the name or email field is executed directly within the backend at /wp-admin/admin.php?page=slickquiz across all users with the privileges of at le

CVE-2019-17385
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The animate-it plugin before 2.3.5 for WordPress has XSS.

CVE-2019-16251
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.

CVE-2019-11807
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

CVE-2019-20209
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.0%
2019 7 PoCs

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.

CVE-2019-17214
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.

CVE-2019-17640
Eclipse Vert.x Windows
N/A
UNKNOWN
EPSS
1.7%
2019 CWE-23 1 PoC

In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Operating systems, allowing, escape the webroot folder to the current working directory.

CVE-2019-15511
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2019 3 PoCs

An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

CVE-2019-14945
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

The ultimate-member plugin before 2.0.54 for WordPress has XSS.

CVE-2019-16932
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2019 2 PoCs

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

CVE-2019-9914
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.

CVE-2019-1010104
Quick Chat WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.

CVE-2019-13570
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2019 2 PoCs

The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.

CVE-2019-16119
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
34.0%
2019 2 PoCs

SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.

CVE-2019-6267
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The Premium WP Suite Easy Redirect Manager plugin 28.07-17 for WordPress has XSS via a crafted GET request that is mishandled during log viewing at the templates/admin/redirect-log.php URI.

CVE-2019-6726
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
3.8%
2019 1 PoC

The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php mishandle ../ in an HTTP Referer header.

CVE-2019-12736
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.

CVE-2019-15830
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

CVE-2019-16223
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
4.3%
2019 3 PoCs

WordPress before 5.2.3 allows XSS in post previews by authenticated users.