11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2014-9098
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the videoadssearchQuery parameter to (1) videoads/videoads.php, (2) video/video.php, or (3) playlist/playlist.php.

CVE-2013-4117
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2013 2 PoCs

Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

CVE-2015-9474
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2015 1 PoC

The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.

CVE-2023-5809
Popup box Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-24534
PhoneTrack Meu Site Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue.

CVE-2015-9437
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.

CVE-2021-24602
HM Multiple Roles Web Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-269 1 PoC

The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page

CVE-2021-25093
Link Library Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-862 1 PoC

The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

CVE-2021-24180
Related Posts for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.

CVE-2021-24619
Per page add to head Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

CVE-2013-6029
Software Genérico Windows
N/A
UNKNOWN
EPSS
5.9%
2013 1 PoC

Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file.

CVE-2021-24585
Timetable and Event Schedule by MotoPress Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-200 2 PoCs

The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the response when requesting the event Timeslot data with a user with the edit_posts capability. Combined with the other Unauthorised Event Timeslot Modification issue (https://wpscan.com/reports/submissions/4699/) where an arbitrary user ID can be set, this could allow low privilege users with the edit_posts capability (such as author) to retrieve sensitive User data by iterating over th

CVE-2021-24700
Forminator – Contact Form, Payment Form & Custom Form Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2021-24473
User Profile Picture Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-639 1 PoC

The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).

CVE-2015-9453
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.

CVE-2023-3130
Short URL Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Short URL WordPress plugin before 1.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2021-22908
Pulse Connect Secure Windows
N/A
UNKNOWN
EPSS
22.7%
2021 CWE-120 1 PoC

A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

CVE-2023-0068
Product GTIN (EAN, UPC, ISBN) for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2007-6236
Software Genérico Windows
N/A
UNKNOWN
EPSS
33.2%
2007 1 PoC

Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demonstrated by kr.aiff.

CVE-2014-9179
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket.