11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-17015
Firefox ESR Windows
N/A
UNKNOWN
EPSS
0.9%
2019 2 PoCs

During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

CVE-2019-19542
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.

CVE-2019-12934
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.

CVE-2014-2558
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2014 1 PoC

The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.

CVE-2015-3442
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.8%
2015 1 PoC

Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API call.

CVE-2019-14799
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.2%
2019 2 PoCs

The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

CVE-2019-20211
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 7 PoCs

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.

CVE-2019-1345
Windows Server Windows
N/A
UNKNOWN
EPSS
5.3%
2019 1 PoC

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1334.

CVE-2019-17235
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.

CVE-2015-9324
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2015 1 PoC

The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.

CVE-2023-2321
WPForms Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2019-14348
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
29.0%
2019 2 PoCs

The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.

CVE-2019-15826
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.

CVE-2023-3460
Ultimate Member Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2023 14 PoCs

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CVE-2019-9912
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2019 2 PoCs

The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.

CVE-2014-8363
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.

CVE-2014-10377
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.

CVE-2015-9230
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.2%
2015 6 PoCs

In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPress, XSS is possible for remote authenticated administrators via the DBTablePrefix parameter.

CVE-2019-0623
Windows Windows
N/A
UNKNOWN
EPSS
34.2%
2019 2 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVE-2019-15109
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.