11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-15780
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

CVE-2019-18278
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the VideoLAN security team indicates that they have not been contacted, and have no way of reproducing this issue.

CVE-2015-9403
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS.

CVE-2019-18368
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.

CVE-2019-0732
Windows Windows
N/A
UNKNOWN
EPSS
0.9%
2019 2 PoCs

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.

CVE-2019-10250
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks.

CVE-2014-5353
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2014 1 PoC

The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.

CVE-2014-7182
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.

CVE-2015-3276
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.6%
2015 1 PoC

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.

CVE-2019-17671
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2019 2 PoCs

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

CVE-2019-17455
Software Genérico Windows
N/A
UNKNOWN
EPSS
7.1%
2019 2 PoCs

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

CVE-2015-6523
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2015 2 PoCs

Cross-site request forgery (CSRF) vulnerability in the Portfolio plugin before 1.05 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the instagram-portfolio page in wp-admin/options-general.php.

CVE-2019-16525
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.8%
2019 2 PoCs

An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.

CVE-2019-14800
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.

CVE-2019-11557
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.

CVE-2019-15316
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2019 3 PoCs

Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.

CVE-2014-4558
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.

CVE-2015-1384
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the banner_effect_divid parameter in the BannerEffectOptions page to wp-admin/options-general.php.

CVE-2019-9909
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 3 PoCs

The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.