11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-1986
Gutentor Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Gutentor WordPress plugin before 3.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-9828
Taskbuilder Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks

CVE-2024-10638
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2022-28790
Link to Windows Service Windows
4.0
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

CVE-2020-15279
Endpoint Security Tools for Windows Windows
4.0
MEDIUM
EPSS
0.1%
2020 CWE-284 1 PoC

An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.

CVE-2024-4755
Google CSE Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5473
Simple Photoswipe Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2021-23883
Endpoint Security (ENS) for Windows Windows
4.0
MEDIUM
EPSS
0.1%
2021 CWE-476 1 PoC

A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to this update.

CVE-2020-7255
McAfee Endpoint Security (ENS) Windows
3.9
LOW
EPSS
0.1%
2020 CWE-264 1 PoC

Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions when editing configuration in the ENS client interface. Administrators can lock the ENS client interface through ePO to prevent users being able to edit the configuration.

CVE-2019-3591
Data Loss Prevention ePO extension Web Windows
3.9
LOW
EPSS
0.2%
2019 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in the ePO UI via a carefully crafted upload to a remote website which is correctly blocked by DLPe Web Protection. This would then render as an XSS when the DLP Admin viewed the event in the ePO UI.

CVE-2020-8956
Software Genérico Windows
3.8
LOW
EPSS
9.2%
2020 1 PoC

Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

CVE-2025-8594
Pz-LinkCard Web Windows
3.8
LOW
EPSS
0.0%
2025 1 PoC

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

CVE-2024-4145
Search & Replace Web Database Windows
3.8
LOW
EPSS
0.5%
2024 1 PoC

The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).

CVE-2024-13116
Crelly Slider Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5030
CM Table Of Contents Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2025-8889
Compress & Upload Web Windows
3.8
LOW
EPSS
0.0%
2025 2 PoCs

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2024-2972
Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3076
MM-email2image Web Windows
3.8
LOW
EPSS
0.1%
2024 1 PoC

The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-3628
EasyEvent Web Windows
3.8
LOW
EPSS
0.2%
2024 1 PoC

The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-3258
Workforce Access Windows
3.7
LOW
EPSS
0.2%
2022 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.