11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-15820
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.

CVE-2019-1262
Microsoft SharePoint Foundation Web Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.

CVE-2019-15839
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 2 PoCs

The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.

CVE-2013-6645
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.4%
2013 1 PoC

Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving certain print-preview and tab-switch actions that interact with a speech input element.

CVE-2015-9323
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.4%
2015 0 PoCs

The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.

CVE-2019-0571
Windows Server 2016 Windows
N/A
UNKNOWN
EPSS
5.1%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0572, CVE-2019-0573, CVE-2019-0574.

CVE-2019-11354
Software Genérico Windows
N/A
UNKNOWN
EPSS
40.7%
2019 8 PoCs

The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.

CVE-2019-0574
Windows Server 2016 Windows
N/A
UNKNOWN
EPSS
1.9%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0571, CVE-2019-0572, CVE-2019-0573.

CVE-2015-1874
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 3 PoCs

Cross-site request forgery (CSRF) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin before 2.8.32 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete all plugin records via a request in the CF7DBPluginSubmissions page to wp-admin/admin.php.

CVE-2019-15770
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.

CVE-2007-0210
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.9%
2007 1 PoC

The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.

CVE-2014-5202
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the search-value parameter.

CVE-2015-9451
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2015 1 PoC

The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.

CVE-2023-28660
Events Made Easy WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.

CVE-2019-12871
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to a Use-After-Free and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

CVE-2015-8467
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.7%
2015 1 PoC

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

CVE-2019-15162
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.

CVE-2019-16097
Software Genérico DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2019 6 PoCs

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVE-2013-5961
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
7.0%
2013 1 PoC

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

CVE-2015-4674
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2015 1 PoC

The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieved without use of SSL, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.