11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-17232
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2019 1 PoC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

CVE-2019-15649
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.

CVE-2007-6438
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.2%
2007 1 PoC

Unspecified vulnerability in the SMB dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service via unknown vectors. NOTE: this identifier originally included MP3 and NCP, but those issues are already covered by CVE-2007-6111.

CVE-2014-8440
Software Genérico Windows
N/A
UNKNOWN
EPSS
88.0%
2014 1 PoC

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8441.

CVE-2013-0900
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.9%
2013 1 PoC

Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVE-2015-9407
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS.

CVE-2023-0219
FluentSMTP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.

CVE-2019-15816
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.

CVE-2019-14950
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2019 0 PoCs

The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

CVE-2015-3647
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.

CVE-2019-13382
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.

CVE-2019-10246
Eclipse Jetty Windows
N/A
UNKNOWN
EPSS
2.6%
2019 CWE-213 7 PoCs

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource directories.

CVE-2019-15778
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.

CVE-2013-0889
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.3%
2013 1 PoC

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitrary code via a crafted file.

CVE-2015-9497
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2015 2 PoCs

The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

CVE-2019-15318
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.

CVE-2019-14467
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
8.6%
2019 3 PoCs

The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.

CVE-2019-14322
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.1%
2019 3 PoCs

In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

CVE-2015-7865
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.6%
2015 2 PoCs

nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users to gain privileges via a commandline in a number 2 command, which is stored in the HKEY_LOCAL_MACHINE explorer Run registry key, a different vulnerability than CVE-2011-4784.

CVE-2019-25060
WPGraphQL Web Windows
N/A
UNKNOWN
EPSS
0.5%
2019 CWE-284 1 PoC

The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.