11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-8968
WordPress Button Plugin MaxButtons Web Windows
4.7
MEDIUM
EPSS
0.5%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11223
WPForms Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5280
wp-affiliate-platform Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack

CVE-2024-2262
Themify Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

CVE-2023-0192
vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
4.7
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and information disclosure.

CVE-2025-9487
Admin and Site Enhancements (ASE) Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc.php when such uploads are enabled, which could allow users to upload a malicious SVG containing XSS payloads

CVE-2025-68947
NSecKrnl Windows
4.7
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

CVE-2024-3754
Alemha watermarker Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-42548
Share-one-Drive Web Windows
4.7
MEDIUM
EPSS
0.8%
2021 CWE-79 1 PoC

Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

CVE-2024-6879
Quiz and Survey Master (QSM) Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.

CVE-2024-1712
Carousel Slider Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3941
reCAPTCHA Jetpack Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-7689
Snapshot Backup Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-3265
Advanced Search Web Database Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.

CVE-2024-2428
The Ultimate Video Player For WordPress Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks

CVE-2024-6723
AI Engine Web Database Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.

CVE-2024-5032
SULly Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-6055
Remote Desktop Manager Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file.

CVE-2021-42549
Lets-Box Web Windows
4.7
MEDIUM
EPSS
0.8%
2021 CWE-79 1 PoC

Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

CVE-2024-3703
Carousel Slider Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Carousel Slider WordPress plugin before 2.2.10 does not validate and escape some of its Slide options before outputting them back in the page/post where the related Slide shortcode is embed, which could allow users with the Editor role and above to perform Stored Cross-Site Scripting attacks