11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2013-5978
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.1%
2013 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php. NOTE: This issue may only cross privilege boundaries if used in combination with CVE-2013-5977.

CVE-2015-0925
Software Genérico Windows
N/A
UNKNOWN
EPSS
68.3%
2015 1 PoC

The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated by a UNC share pathname.

CVE-2023-5209
WordPress Online Booking and Scheduling Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2019-6703
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.7%
2019 1 PoC

Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

CVE-2019-14683
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

CVE-2019-17237
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.

CVE-2015-9499
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.9%
2015 2 PoCs

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

CVE-2019-11872
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.

CVE-2019-6265
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The Scripting and AutoUpdate functionality in Cordaware bestinformed Microsoft Windows client versions before 6.2.1.0 are affected by insecure implementations which allow remote attackers to execute arbitrary commands and escalate privileges.

CVE-2019-15828
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.

CVE-2019-13344
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
58.1%
2019 3 PoCs

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

CVE-2014-6540
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.34, before 4.2.26, and before 4.3.14 allows local users to affect availability via vectors related to Graphics driver (WDDM) for Windows guests.

CVE-2013-7332
Software Genérico Windows
N/A
UNKNOWN
EPSS
13.9%
2013 1 PoC

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVE-2015-2220
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php.

CVE-2019-9855
LibreOffice Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added to block calling LibreLogo from script event handers. However a Windows 8.3 path equivalence handling flaw left LibreOffice vulnerable under Windows that a document could trigger executing LibreLogo via a Windows filename pseudony

CVE-2019-5676
NVIDIA GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.

CVE-2019-0573
Windows Server 2016 Windows
N/A
UNKNOWN
EPSS
10.3%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0571, CVE-2019-0572, CVE-2019-0574.

CVE-2019-6145
Forcepoint VPN Client for Windows Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs for finding this vulnerability and for reporting it to us.

CVE-2015-4616
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
15.3%
2015 1 PoC

Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.

CVE-2019-14206
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.8%
2019 2 PoCs

An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php.