555 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-16273
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. Also, this provides a covert ability to capture screen data from the Zoom Client on Windows by executing commands on the Android OS.

CVE-2019-1010104
Quick Chat WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.

CVE-2019-13570
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2019 2 PoCs

The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.

CVE-2019-16119
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
34.0%
2019 2 PoCs

SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.

CVE-2019-6267
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The Premium WP Suite Easy Redirect Manager plugin 28.07-17 for WordPress has XSS via a crafted GET request that is mishandled during log viewing at the templates/admin/redirect-log.php URI.

CVE-2019-6726
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
3.8%
2019 1 PoC

The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php mishandle ../ in an HTTP Referer header.

CVE-2019-12736
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.

CVE-2019-19521
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).

CVE-2019-15830
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

CVE-2019-16223
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
4.3%
2019 3 PoCs

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVE-2019-3974
Tenable Nessus Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwritten arbitrarily, potentially creating a denial of service condition.

CVE-2019-9966
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c.

CVE-2019-15645
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.

CVE-2019-13578
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
3.0%
2019 1 PoC

A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.

CVE-2019-17229
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.

CVE-2019-17388
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.

CVE-2019-1108
Windows Windows
N/A
UNKNOWN
EPSS
23.5%
2019 1 PoC

An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.

CVE-2019-20041
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.4%
2019 1 PoC

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVE-2019-15781
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.

CVE-2019-11700
Firefox Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.