11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2007-1644
Software Genérico Windows
N/A
UNKNOWN
EPSS
31.7%
2007 1 PoC

The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).

CVE-2014-9119
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
51.1%
2014 2 PoCs

Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2023-28661
WP Popup Banners WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action.

CVE-2019-20181
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.

CVE-2019-16647
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.

CVE-2019-13569
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
2.7%
2019 1 PoC

A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

CVE-2019-9787
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
81.0%
2019 6 PoCs

WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.

CVE-2019-15870
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.

CVE-2019-14798
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.7%
2019 2 PoCs

The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.

CVE-2023-5737
WordPress Backup & Migration Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

CVE-2019-11565
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.4%
2019 2 PoCs

Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.

CVE-2019-17009
Thunderbird Windows
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVE-2023-3131
MStore API Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

CVE-2019-0881
Windows Windows
N/A
UNKNOWN
EPSS
4.3%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege Vulnerability'.

CVE-2013-7276
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in inc/raf_form.php in the Recommend to a friend plugin 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the current_url parameter.

CVE-2015-4851
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
1.4%
2015 3 PoCs

Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to XML input. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a denial of service, or conduct SMB Relay attacks via a crafted DTD in an XML request to OA_HTML/oramipp_lpr.

CVE-2023-0263
WP Yelp Review Slider Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2019-15742
Software Genérico Windows
N/A
UNKNOWN
EPSS
8.8%
2019 1 PoC

A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application. A local attacker can exploit this issue to gain elevated privileges.

CVE-2019-15832
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.

CVE-2019-1006
Windows Windows
N/A
UNKNOWN
EPSS
2.7%
2019 1 PoC

An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.