11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-14682
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page CSRF.

CVE-2015-2199
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.8%
2015 1 PoC

Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL commands via the itemid parameter in the (2) wonderplugin_audio_show_item, (3) wonderplugin_audio_show_items, or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php.

CVE-2023-5672
WP Mail Log Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

CVE-2019-13413
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.

CVE-2019-13573
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
4.6%
2019 1 PoC

A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

CVE-2019-8943
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2019 6 PoCs

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVE-2019-12828
Software Genérico Windows
N/A
UNKNOWN
EPSS
11.7%
2019 3 PoCs

An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath argument supplied with a Windows network share.

CVE-2014-9422
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.8%
2014 1 PoC

The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 allows remote authenticated users to bypass a kadmin/* authorization check and obtain administrative access by leveraging access to a two-component principal with an initial "kadmind" substring, as demonstrated by a "ka/x" principal.

CVE-2013-0881
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
0.7%
2013 1 PoC

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via crafted data in the Matroska container format.

CVE-2015-8642
Software Genérico Windows
N/A
UNKNOWN
EPSS
5.0%
2015 3 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.

CVE-2023-20568
Radeon™ RX 5000/6000/7000 Series Graphics Cards Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

CVE-2019-12239
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.

CVE-2019-17675
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVE-2015-1787
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
25.8%
2015 8 PoCs

The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to cause a denial of service (daemon crash) via a ClientKeyExchange message with a length of zero.

CVE-2019-14680
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.

CVE-2019-15769
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.

CVE-2019-14220
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.2%
2019 3 PoCs

An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS. Bug is in a local arbitrary file read through a system service call. The impacted method runs with System admin privilege and if given the file name as parameter returns you the content of file. A malicious app using the affected method can then read the content of any system file which it is not authorized to read

CVE-2019-14695
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2019 1 PoC

A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.

CVE-2013-6646
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.8%
2013 1 PoC

Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the shutting down of a worker process.

CVE-2015-9391
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.9%
2015 1 PoC

The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.