11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-9567
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2019 3 PoCs

The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.

CVE-2019-7300
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.7%
2019 1 PoC

Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_password fields, using these credentials at logon.php, and then entering the commands in the admin.index.php command-line field.

CVE-2019-15817
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The easy-property-listings plugin before 3.4 for WordPress has XSS.

CVE-2019-15627
Deep Security Agent Windows
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability impact. Local OS access is required. Please note that only Windows agents are affected.

CVE-2019-9730
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
6.8%
2019 1 PoC

Incorrect access control in the CxUtilSvc component of the Synaptics Sound Device drivers prior to version 2.29 allows a local attacker to increase access privileges to the Windows Registry via an unpublished API.

CVE-2019-0785
Windows Server Windows
N/A
UNKNOWN
EPSS
51.5%
2019 1 PoC

A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

CVE-2023-5610
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect

CVE-2019-11886
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
22.1%
2019 3 PoCs

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

CVE-2014-8622
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the search-value parameter.

CVE-2013-0236
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

CVE-2019-15300
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.

CVE-2019-15873
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
9.6%
2019 1 PoC

The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.

CVE-2019-15827
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.

CVE-2019-17672
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
5.3%
2019 1 PoC

WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

CVE-2019-14773
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.

CVE-2023-2628
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)

CVE-2013-3136
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.0%
2013 1 PoC

The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."

CVE-2015-1376
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
70.5%
2015 3 PoCs

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

CVE-2019-3467
Debian Edu Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.