1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-2761
Genesis Blocks Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.

CVE-2024-5077
wp-eMember Web Windows
6.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-2907
AGCA Web Windows
6.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The AGCA WordPress plugin before 7.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3901
Genesis Blocks Web Windows
6.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.

CVE-2024-10709
YaDisk Files Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-4977
Index WP MySQL For Speed Web Database Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-2640
Watu Quiz Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2024-13347
Essential WP Real Estate Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2024-5744
wp-eMember Web Windows
6.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-28589
Software Genérico Windows
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during service initialization.

CVE-2024-21107
VM VirtualBox Database Windows
6.7
MEDIUM
EPSS
0.1%
2024 2 PoCs

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows hosts only. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/

CVE-2024-21302
Windows 10 Version 1809 Cloud Windows
6.7
MEDIUM
EPSS
1.1%
2024 CWE-284 1 PoC

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files wi

CVE-2024-9422
GEO my WP Web Windows
6.6
MEDIUM
EPSS
0.6%
2024 1 PoC

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

CVE-2024-23772
Software Genérico Windows
6.6
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.

CVE-2024-9529
Secure Custom Fields Web Windows
6.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.

CVE-2024-6412
HTML Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-1747
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.

CVE-2024-7714
AI ChatBot with ChatGPT and Content Generator by AYS Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
23.9%
2024 1 PoC

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CVE-2024-4533
KKProgressbar2 Free Web Database Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to perform SQL injection attacks