11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2007-3039
Software Genérico Windows
N/A
UNKNOWN
EPSS
83.4%
2007 4 PoCs

Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.

CVE-2014-7138
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php.

CVE-2013-5962
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
26.6%
2013 3 PoCs

Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.

CVE-2021-24518
WPFront Notification Bar Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 2 PoCs

The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-25118
Yoast SEO Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
35.3%
2021 CWE-200 1 PoC

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

CVE-2021-25090
Portfolio Gallery, Product Catalog – Grid KIT Portfolio Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embed

CVE-2015-2062
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2015 1 PoC

Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it_slider page to wp-admin/admin.php.

CVE-2021-24227
Patreon WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
38.7%
2021 CWE-200 0 PoCs

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.

CVE-2021-24661
PostX – Gutenberg Blocks for Post Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-200 1 PoC

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.

CVE-2021-24736
Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.

CVE-2021-24904
Mortgage Calculators WP Web Windows
N/A
UNKNOWN
EPSS
3.0%
2021 CWE-79 1 PoC

The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2013-4240
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2013 2 PoCs

Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the hms-testimonials-addnew page, (2) add new groups via the hms-testimonials-addnewgroup page, (3) change default settings via the hms-testimonials-settings page, (4) change advanced settings via the hms-testimonials-settings-advanced page, (5) change custom fields settings via the hms-testimonials-settings-fields page, or (6) change template settings via the hm

CVE-2015-5129
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.8%
2015 3 PoCs

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5541.

CVE-2023-2398
Icegram Engage Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-25120
Easy Social Feed Pro Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.6%
2021 CWE-79 1 PoC

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

CVE-2021-24859
User meta shortcodes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-284 1 PoC

The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

CVE-2015-6677
Software Genérico Windows
N/A
UNKNOWN
EPSS
6.4%
2015 3 PoCs

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-5588.

CVE-2021-24910
Transposh WordPress Translation Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.6%
2021 CWE-79 1 PoC

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24720
Business Directory Plugin | GeoDirectory Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-79 1 PoC

The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).

CVE-2014-2044
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
13.9%
2014 2 PoCs

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.