11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-14746
Applications Framework Web Database Windows
4.7
MEDIUM
EPSS
0.7%
2020 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popup windows). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update,

CVE-2023-1112
Drag and Drop Multiple File Upload Contact Form 7 Web Windows
4.7
MEDIUM
EPSS
31.8%
2023 CWE-23 1 PoC

A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222072.

CVE-2023-32019
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
2.8%
2023 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2025-4955
tarteaucitron.io Web Windows
4.7
MEDIUM
EPSS
0.3%
2025 1 PoC

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVE-2025-0522
LikeBot Web Windows
4.7
MEDIUM
EPSS
0.1%
2025 1 PoC

The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2025-9541
Markup Markdown Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-12569
Guest posting / Frontend Posting / Front Editor Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2024-6073
wp-cart-for-digital-products Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-2159
Social Sharing Plugin Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5575
Ditty Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2025-9540
Markup Markdown Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5727
Widget4Call Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2022-2546
All-in-One WP Migration Web Windows ⚡ nuclei
4.7
MEDIUM
EPSS
16.2%
2022 5 PoCs

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

CVE-2024-1754
NPS computy Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-21766
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
6.4%
2023 CWE-591 1 PoC

Windows Overlay Filter Information Disclosure Vulnerability

CVE-2024-4217
shortcodes-ultimate-pro Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.

CVE-2024-1292
wpb-show-core Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-10903
Broken Link Checker Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.

CVE-2024-8968
WordPress Button Plugin MaxButtons Web Windows
4.7
MEDIUM
EPSS
0.5%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).