11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2013-0891
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2013 1 PoC

Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a blob.

CVE-2015-3326
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2015 1 PoC

Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote attackers to bypass authentication via a brute force attack.

CVE-2019-17233
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

CVE-2019-14947
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.

CVE-2023-20561
μProf Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary address potentially resulting in a Windows crash leading to denial of service.

CVE-2019-10869
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
48.0%
2019 2 PoCs

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.

CVE-2019-19306
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.

CVE-2015-4010
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.4%
2015 4 PoCs

Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the iframe_url parameter in an Update Page action in the conformconf page to wp-admin/options-general.php.

CVE-2023-5611
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them

CVE-2019-12826
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.

CVE-2019-16414
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 3 PoCs

A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's cleartext credentials to an attacker via a login/?reason=failure&NTLM= URI.

CVE-2019-0735
Windows Windows
N/A
UNKNOWN
EPSS
9.7%
2019 2 PoCs

An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'.

CVE-2007-2896
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.6%
2007 1 PoC

Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.

CVE-2007-2442
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
42.6%
2007 3 PoCs

The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.

CVE-2007-3140
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
2.6%
2007 1 PoC

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

CVE-2007-0433
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.3%
2007 1 PoC

Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.

CVE-2007-0045
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
61.4%
2007 5 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."

CVE-2014-6490
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.7%
2014 1 PoC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to SMB server user component.

CVE-2015-9404
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS.

CVE-2019-14979
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state