1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-28830
TIBCO Enterprise Runtime for R - Server Edition Cloud Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Statistics Services, TIBCO Spotfire Statistics Services, and TIBCO Spotfire Statistics Services contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating sy

CVE-2021-27660
C-CURE 9000 Windows
8.8
HIGH
EPSS
1.2%
2021 CWE-20 1 PoC

An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.

CVE-2021-28821
TIBCO Enterprise Message Service Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files

CVE-2021-28826
TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions

CVE-2021-21911
Advantech Windows
8.8
HIGH
EPSS
0.0%
2021 CWE-276 1 PoC

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-23893
McAfee Drive Encryption (MDE) Windows
8.8
HIGH
EPSS
0.0%
2021 CWE-269 1 PoC

Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.

CVE-2021-28825
TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on c

CVE-2021-38666
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
31.9%
2021 1 PoC

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2021-21910
Advantech Windows
8.8
HIGH
EPSS
0.0%
2021 CWE-276 1 PoC

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-42362
WordPress Popular Posts Web Windows
8.8
HIGH
EPSS
77.5%
2021 CWE-434 3 PoCs

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.

CVE-2021-24566
FOX Web Windows
8.8
HIGH
EPSS
1.8%
2021 1 PoC

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

CVE-2021-4401
Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns Web Windows
8.8
HIGH
EPSS
0.4%
2021 CWE-352 7 PoCs

The Style Kits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.0. This is due to missing or incorrect nonce validation on the update_posts_stylekit() function. This makes it possible for unauthenticated attackers to update style kits for posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4373
Better Search – Relevant search results for WordPress Web Windows
8.8
HIGH
EPSS
0.1%
2021 CWE-288 1 PoC

The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to import settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-24869
WP Fastest Cache Web Database Windows
8.8
HIGH
EPSS
0.6%
2021 1 PoC

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber

CVE-2021-34527
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
94.2%
2021 22 PoCs

<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>UPDATE July 7, 2021: The security update for Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607 have been released. Please see the Security Updates table for the applicable update for your system. We recommend that

CVE-2021-23275
TIBCO Enterprise Runtime for R - Server Edition Cloud Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Statistics Services, TIBCO Spotfire Statistics Services, and TIBCO Spotfire Statistics Services contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert mali

CVE-2021-28823
TIBCO eFTL - Community Edition Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected