11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2013-3167
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.9%
2013 1 PoC

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Information Disclosure Vulnerability."

CVE-2015-8351
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
69.4%
2015 7 PoCs

PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.

CVE-2021-24671
MX Time Zone Clocks Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-24899
Media Tags Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.

CVE-2023-5749
EmbedPress Web Windows
N/A
UNKNOWN
EPSS
1.5%
2023 1 PoC

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-24779
WP Debugging Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users.

CVE-2015-5535
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in the qTranslate plugin 2.5.39 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the edit parameter in the qtranslate page to wp-admin/options-general.php.

CVE-2021-24220
Rise by Thrive Themes Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
63.8%
2021 CWE-434 2 PoCs

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using th

CVE-2021-24159
Contact Form 7 Style Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or attachment, then the request could be sent and the CSS settings would be successfully updated to include malicious JavaScript.

CVE-2021-24376
Autoptimize Web Windows
N/A
UNKNOWN
EPSS
10.0%
2021 CWE-434 1 PoC

The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and then it is not removed from the disk. It is a bypass of CVE-2020-24948 which allows sending a PHP file via the "Import Settings" functionality to achieve Remote Code Execution.

CVE-2021-24407
Jannah Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.0%
2021 CWE-79 1 PoC

The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.

CVE-2021-24244
WPBakery Page Builder (Visual Composer) Clipboard Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).

CVE-2013-4656
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.7%
2013 1 PoC

Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.

CVE-2015-5057
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before 1.10.9 is installed.

CVE-2023-2309
wpForo Forum Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.2%
2023 1 PoC

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.

CVE-2021-25028
Event Tickets Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2021 CWE-601 1 PoC

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

CVE-2021-25108
IP2Location Country Blocker Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

CVE-2015-9307
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.

CVE-2023-5765
Remote Desktop Manager Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.

CVE-2007-4414
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box.