11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-4032
FreeRDP Windows
3.1
LOW
EPSS
0.4%
2020 CWE-681 1 PoC

In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.

CVE-2023-2282
Remote Desktop Manager Windows
3.1
LOW
EPSS
0.3%
2023 1 PoC

Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.

CVE-2023-39202
Zoom Rooms Client for Windows and Zoom VDI Client Windows
3.1
LOW
EPSS
0.0%
2023 CWE-426 1 PoC

Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

CVE-2024-22371
Apache Camel Web Windows
2.9
LOW
EPSS
0.9%
2024 1 PoC

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

CVE-2023-31028
nvJPEG2000 Library Windows
2.8
LOW
EPSS
0.0%
2023 CWE-20 1 PoC

NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.

CVE-2023-28602
Zoom for Windows Client Windows
2.8
LOW
EPSS
0.1%
2023 CWE-347 1 PoC

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

CVE-2024-53921
Software Genérico Windows
2.8
LOW
EPSS
0.1%
2024 1 PoC

An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.

CVE-2024-0080
nvTIFF Library Windows
2.8
LOW
EPSS
0.0%
2024 CWE-20 1 PoC

NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.

CVE-2022-4109
Wholesale Market for WooCommerce Web Windows
2.7
LOW
EPSS
0.3%
2022 1 PoC

The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)

CVE-2025-10723
PixelYourSite Web Windows
2.7
LOW
EPSS
0.1%
2025 1 PoC

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks

CVE-2023-4216
Orders Tracking for WooCommerce Web Windows
2.7
LOW
EPSS
0.1%
2023 1 PoC

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first line of the file.

CVE-2025-12954
Timetable and Event Schedule by MotoPress Web Windows
2.7
LOW
EPSS
0.0%
2025 1 PoC

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor.

CVE-2024-6694
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Web Windows
2.7
LOW
EPSS
3.3%
2024 CWE-257 1 PoC

The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated attackers, with administrative-level access and above, to view the SMTP password for the supplied server. Although this would not be useful for attackers in most cases, if an administrator account becomes compromised this could be useful information to an attacker in a limited environment.

CVE-2025-12654
WPvivid — Backup, Migration & Staging Web Windows
2.7
LOW
EPSS
0.0%
2025 CWE-73 2 PoCs

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location. This makes it possible for authenticated attackers, with Administrator-level access and above, to create arbitrary directories.

CVE-2024-10562
Form Maker by 10Web Web Windows
2.7
LOW
EPSS
0.2%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10102
Photo Gallery, Images, Slider in Rbs Image Gallery Web Windows
2.7
LOW
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-10098
ApplyOnline Web Windows
2.7
LOW
EPSS
0.3%
2024 1 PoC

The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

CVE-2024-8350
Uncanny Groups for LearnDash Web Windows
2.7
LOW
EPSS
0.2%
2024 CWE-862 1 PoC

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and above, to add users to their group which ultimately allows them to leverage CVE-2024-8349 and gain admin access to the site.

CVE-2023-2252
Directorist Web Windows ⚡ nuclei
2.7
LOW
EPSS
7.8%
2023 1 PoC

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

CVE-2023-2117
Image Optimizer by 10web Web Windows
2.7
LOW
EPSS
0.2%
2023 1 PoC

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.