11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-4004
Advanced Cron Manager Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-33597
F-Secure endpoint protection products on Windows, Mac and Linux Security Web Windows
3.5
LOW
EPSS
0.1%
2021 1 PoC

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

CVE-2024-6792
WP ULike Web Windows
3.5
LOW
EPSS
0.2%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page.

CVE-2024-10545
Photo Gallery, Sliders, Proofing and Themes Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-7297
TwitterPosts Web Windows
3.5
LOW
EPSS
0.1%
2023 1 PoC

The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-12767
buddyboss-platform Web Windows
3.5
LOW
EPSS
0.1%
2024 1 PoC

The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts

CVE-2023-4973
LMS Windows ⚡ nuclei
3.5
LOW
EPSS
5.0%
2023 CWE-79 2 PoCs

A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument searched_word/searched_tution_class_type[]/searched_price_type[]/searched_duration[] leads to cross site scripting. The attack can be launched remotely. The identifier VDB-239749 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3471
Button Generator Web Windows
3.4
LOW
EPSS
0.1%
2024 1 PoC

The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

CVE-2022-28764
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Database Windows
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

CVE-2022-28766
Zoom Client for Meetings for Windows (32-bit) Windows
3.3
LOW
EPSS
0.4%
2022 CWE-94 1 PoC

Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.

CVE-2023-28351
Software Genérico Windows
3.3
LOW
EPSS
0.0%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially enabling them to obtain PII and/or to compromise personal accounts owned by the victim.

CVE-2025-55307
Software Genérico Web Windows
3.3
LOW
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds read in internal path-parsing logic, potentially leading to information disclosure or memory corruption.

CVE-2026-0747
Remote Desktop Manager Windows
3.3
LOW
EPSS
0.0%
2026 CWE-200 1 PoC

Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing.

CVE-2024-5198
ovpn-dco Networking Windows
3.3
LOW
EPSS
0.1%
2024 CWE-476 1 PoC

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

CVE-2023-3666
Sticky Side Buttons Web Windows
3.3
LOW
EPSS
0.0%
2023 1 PoC

The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-28312
Windows 10 Version 1809 Windows
3.3
LOW
EPSS
8.3%
2021 1 PoC

Windows NTFS Denial of Service Vulnerability

CVE-2022-4309
Subscribe2 Web Windows
3.1
LOW
EPSS
0.1%
2022 1 PoC

The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing their email via a CSRF attack.

CVE-2022-4102
Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets) Web Windows
3.1
LOW
EPSS
0.1%
2022 1 PoC

The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug.

CVE-2018-0878
Windows Remote Assistance Windows
3.1
LOW
EPSS
41.8%
2018 1 PoC

Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how XML External Entities (XXE) are processed, aka "Windows Remote Assistance Information Disclosure Vulnerability".

CVE-2020-4033
FreeRDP Windows
3.1
LOW
EPSS
0.2%
2020 CWE-125 1 PoC

In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.