11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-15598
treekill Windows
N/A
UNKNOWN
EPSS
3.8%
2019 CWE-94 1 PoC

A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

CVE-2019-15858
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.2%
2019 3 PoCs

admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.

CVE-2015-3196
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
7.4%
2015 10 PoCs

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

CVE-2019-20204
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.9%
2019 3 PoCs

The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.

CVE-2019-12889
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to NT AUTHORITY\System. An attacker would need local access to the machine for a successful exploit. The attacker must disconnect the computer from the local network / WAN and connect it to an internet facing access point / network. At that point, the attacker can execute the password-reset functionality, which will expose a web browser. Browsing to a site that calls local Windows system functions (e.g., file upload) wil

CVE-2019-6112
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2019 1 PoC

A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

CVE-2019-13702
Chrome Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.

CVE-2014-5187
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2014 0 PoCs

Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files via the file parameter to tom-download-file.php.

CVE-2015-8449
Software Genérico Windows
N/A
UNKNOWN
EPSS
7.5%
2015 3 PoCs

Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a crafted lineTo method call, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2

CVE-2023-2225
SEO ALert Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2019-18895
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2019 3 PoCs

Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.

CVE-2019-15865
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.

CVE-2019-1347
Windows Windows
N/A
UNKNOWN
EPSS
27.0%
2019 1 PoC

A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1343, CVE-2019-1346.

CVE-2015-3314
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
8.8%
2015 2 PoCs

SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.

CVE-2019-15838
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.

CVE-2019-16250
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.

CVE-2019-15644
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.

CVE-2019-16220
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.

CVE-2007-0111
Software Genérico Windows
N/A
UNKNOWN
EPSS
5.5%
2007 1 PoC

Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image.

CVE-2014-1715
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact and attack vectors.