11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-7413
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In the Parallax Scroll (aka adamrob-parallax-scroll) plugin before 2.1 for WordPress, includes/adamrob-parralax-shortcode.php allows XSS via the title text. ("parallax" has a spelling change within the PHP filename.)

CVE-2019-15321
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.

CVE-2015-3301
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
14.4%
2015 2 PoCs

Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.

CVE-2019-15713
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2019 0 PoCs

The my-calendar plugin before 3.1.10 for WordPress has XSS.

CVE-2019-0570
Windows Server 2012 R2 Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

CVE-2019-3999
Druva inSync Windows Client Windows
N/A
UNKNOWN
EPSS
16.6%
2019 3 PoCs

Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

CVE-2019-1343
Windows Server Windows
N/A
UNKNOWN
EPSS
31.3%
2019 1 PoC

A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.

CVE-2007-0221
Software Genérico Windows
N/A
UNKNOWN
EPSS
65.0%
2007 1 PoC

Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."

CVE-2007-0946
Software Genérico Windows
N/A
UNKNOWN
EPSS
59.5%
2007 1 PoC

Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.

CVE-2007-2730
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
0.0%
2007 1 PoC

Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.

CVE-2014-3850
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

Cross-site request forgery (CSRF) vulnerability in the Member Approval plugin 131109 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings to their default and disable registration approval via a request to wp-admin/options-general.php.

CVE-2013-7049
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.1%
2013 1 PoC

Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earlier, allows remote attackers to cause a denial of service (crash) via a long string in a DH1080_INIT message.

CVE-2015-5132
Software Genérico Windows
N/A
UNKNOWN
EPSS
71.5%
2015 4 PoCs

Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5133.

CVE-2023-4922
wpb-show-core Web Windows
N/A
UNKNOWN
EPSS
26.4%
2023 1 PoC

The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.

CVE-2019-5666
NVIDIA GPU Graphics Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2019 2 PoCs

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) create context command DDI DxgkDdiCreateContext in which the product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array, which may lead to denial of service or escalation of privileges.

CVE-2019-15824
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.

CVE-2019-14313
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
4.1%
2019 1 PoC

A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.

CVE-2015-0240
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
90.7%
2015 4 PoCs

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVE-2019-9969
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399.

CVE-2019-1241
Windows Windows
N/A
UNKNOWN
EPSS
29.4%
2019 1 PoC

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.