11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-9965
Chrome Windows
8.8
HIGH
EPSS
1.7%
2024 1 PoC

Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

CVE-2021-28826
TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions

CVE-2024-11643
Accessibility by AllAccessible Web Windows
8.8
HIGH
EPSS
1.5%
2024 CWE-862 1 PoC

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'AllAccessible_save_settings' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVE-2023-6140
Essential Real Estate Web Windows
8.8
HIGH
EPSS
3.9%
2023 1 PoC

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

CVE-2023-0259
WP Google Review Slider Web Database Windows
8.8
HIGH
EPSS
0.5%
2023 1 PoC

The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2021-24566
FOX Web Windows
8.8
HIGH
EPSS
1.8%
2021 1 PoC

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

CVE-2024-10578
Pubnews Web Windows
8.8
HIGH
EPSS
51.0%
2024 CWE-434 1 PoC

The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer_plugin_action_for_notice() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins that can be leveraged to exploit other vulnerabilities.

CVE-2023-39211
Zoom Desktop Client for Windows and Zoom Rooms for Windows Windows
8.8
HIGH
EPSS
0.0%
2023 CWE-347 1 PoC

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

CVE-2023-38043
Secure Access Client Windows Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.

CVE-2023-4643
Enable Media Replace Web Windows
8.8
HIGH
EPSS
0.4%
2023 1 PoC

The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog

CVE-2023-21674
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
11.6%
2023 CWE-416 1 PoC

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVE-2021-28825
TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on c

CVE-2023-0820
User Role by BestWebSoft Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

CVE-2023-0765
Gallery by BestWebSoft Web Database Windows
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable.

CVE-2023-21742
Microsoft SharePoint Enterprise Server 2016 Windows
8.8
HIGH
EPSS
16.5%
2023 CWE-284 1 PoC

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2023-2843
MultiParcels Shipping For WooCommerce Web Database Windows
8.8
HIGH
EPSS
0.4%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

CVE-2024-11638
Gtbabel Web Windows
8.8
HIGH
EPSS
0.5%
2024 1 PoC

The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies.

CVE-2023-24871
Windows Server 2022 Windows
8.8
HIGH
EPSS
59.6%
2023 CWE-190 1 PoC

Windows Bluetooth Service Remote Code Execution Vulnerability

CVE-2023-35674
🔥 KEV Android Windows
8.8
HIGH
EPSS
0.1%
2023 2 PoCs

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2021-23893
McAfee Drive Encryption (MDE) Windows
8.8
HIGH
EPSS
0.0%
2021 CWE-269 1 PoC

Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.