11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-41065
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the attacker will be able to duplicate the victim's token to impersonate him. This exploit is valid in certain Windows versions (Microsoft has patched the issue in later Windows 10 builds).

CVE-2015-8638
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.3%
2015 3 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8635, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.

CVE-2023-0377
Scriptless Social Sharing Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Scriptless Social Sharing WordPress plugin before 3.2.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2021-24615
微信打赏(Wechat Reward) Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.

CVE-2021-25276
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a valid profile file to this directory. For example, if this profile sets up a user with a C:\ home directory, then the attacker obtains access to read or replace arbitrary files with LocalSystem privileges.

CVE-2021-24181
Tutor LMS – eLearning and online course solution Web Database Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-89 1 PoC

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

CVE-2007-4415
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.0%
2007 1 PoC

Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.

CVE-2007-2224
Software Genérico Windows
N/A
UNKNOWN
EPSS
70.6%
2007 1 PoC

Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.

CVE-2007-0211
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.4%
2007 1 PoC

The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."

CVE-2014-0508
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.6%
2014 1 PoC

Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.

CVE-2013-7129
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in ThemeBeans Blooog theme 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the jQuery parameter to assets/js/jplayer.swf.

CVE-2015-9462
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2015 1 PoC

The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.

CVE-2021-24560
Software License Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24174
Database Backups Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-352 2 PoCs

The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.

CVE-2023-2029
PrePost SEO Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-24735
Compact WP Audio Player Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

CVE-2015-6827
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 2 PoCs

Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php.

CVE-2021-24410
తెలుగు బైబిల్ వచనములు Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses containing JavaScript code in them, leading to Stored XSS issues

CVE-2021-25025
EventCalendar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

CVE-2021-24920
StatCounter – Free Real Time Visitor Stats Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed