11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-12046
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

LemonLDAP::NG -2.0.3 has Incorrect Access Control.

CVE-2014-5196
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

Cross-site request forgery (CSRF) vulnerability in improved-user-search-in-backend.php in the backend in the Improved user search in backend plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that insert XSS sequences via the iusib_meta_fields parameter.

CVE-2013-6182
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

Unquoted Windows search path vulnerability in EMC Replication Manager before 5.5 allows local users to gain privileges via a crafted application in a parent directory of an intended directory.

CVE-2015-3904
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
0.6%
2015 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php in the Roomcloud plugin before 1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) pin, (2) start_day, (3) start_month, (4) start_year, (5) end_day, (6) end_month, (7) end_year, (8) lang, (9) adults, or (10) children parameter.

CVE-2019-17384
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The animate-it plugin before 2.3.4 for WordPress has XSS.

CVE-2023-3182
Membership Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2019-16218
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.4%
2019 1 PoC

WordPress before 5.2.3 allows XSS in stored comments.

CVE-2015-20106
ClickBank Affiliate Ads Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 CWE-79 1 PoC

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2019-5694
NVIDIA GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service or information disclosure through code execution. The attacker requires local system access.

CVE-2019-15116
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.

CVE-2013-0077
Software Genérico Windows
N/A
UNKNOWN
EPSS
53.0%
2013 1 PoC

Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."

CVE-2015-5485
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2015 3 PoCs

Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php.

CVE-2019-15326
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

CVE-2019-14788
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.6%
2019 2 PoCs

wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.

CVE-2015-3302
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
20.6%
2015 2 PoCs

The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."

CVE-2019-5669
NVIDIA GPU Graphics Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2019 2 PoCs

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape in which the software uses a sequential operation to read from or write to a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer, which may lead to denial of service or escalation of privileges.

CVE-2019-1096
Windows Windows
N/A
UNKNOWN
EPSS
34.6%
2019 1 PoC

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

CVE-2023-6272
tml-2fa Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

CVE-2019-17387
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.

CVE-2007-0220
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
43.7%
2007 1 PoC

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".