11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2015-9500
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.

CVE-2019-19916
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could result in script running where CSP should have blocked it, allowing for cross-site scripting (XSS) and other attacks when the product renders the content as HTML. Remediating this would also need to consider the polyglot case, e.g., a file that is a valid GIF image and also valid JavaScript.

CVE-2019-15324
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
8.1%
2019 1 PoC

The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.

CVE-2019-1089
Multiple Windows
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. To exploit this vulnerability, a low level authenticated attacker could run a specially crafted application. The security update addresses this vulnerability by correcting how rpcss.dll handles these requests., aka 'Windows RPCSS Elevation of Privilege Vulnerability'.

CVE-2019-9967
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString.

CVE-2014-6444
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2014 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to iframe-googlefont-preview.php or the (2) text parameter to iframe-font-preview.php.

CVE-2013-0896
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2013 1 PoC

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly manage memory during message handling for plug-ins, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVE-2015-9447
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2015 2 PoCs

The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.

CVE-2023-38429
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.

CVE-2019-0730
Windows Windows
N/A
UNKNOWN
EPSS
3.1%
2019 2 PoCs

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.

CVE-2019-5683
GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the user mode video driver trace logger component. When an attacker has access to the system and creates a hard link, the software does not check for hard link attacks. This behavior may lead to code execution, denial of service, or escalation of privileges.

CVE-2019-14796
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.

CVE-2015-8429
Software Genérico Windows
N/A
UNKNOWN
EPSS
77.9%
2015 4 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015

CVE-2023-5990
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not have CSRF checks on some of its form actions such as deletion and duplication, which could allow attackers to make logged in admin perform such actions via CSRF attacks

CVE-2019-14327
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.

CVE-2019-13275
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.2%
2019 1 PoC

An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.

CVE-2013-3526
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.2%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the aoid parameter.

CVE-2015-9405
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

The wp-piwik plugin before 1.0.5 for WordPress has XSS.

CVE-2019-12241
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.

CVE-2019-17670
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
5.5%
2019 2 PoCs

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.