11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2007-3846
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.3%
2007 1 PoC

Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository.

CVE-2007-2219
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
58.5%
2007 1 PoC

Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.

CVE-2007-5997
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.4%
2007 1 PoC

SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

CVE-2007-4490
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.1%
2007 1 PoC

Multiple buffer overflows in EarthAgent.exe in Trend Micro ServerProtect 5.58 for Windows before Security Patch 4 allow remote attackers to have an unknown impact via certain RPC function calls to (1) RPCFN_EVENTBACK_DoHotFix or (2) CMD_CHANGE_AGENT_REGISTER_INFO.

CVE-2007-1658
Software Genérico Windows
N/A
UNKNOWN
EPSS
76.6%
2007 3 PoCs

Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).

CVE-2014-8145
Software Genérico Windows
N/A
UNKNOWN
EPSS
13.0%
2014 2 PoCs

Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function.

CVE-2013-6853
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2013 2 PoCs

Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim.

CVE-2015-3107
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.8%
2015 1 PoC

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3103 and CVE-2015-3106.

CVE-2021-25113
Dropdown Menu Widget Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2021-24606
Availability Calendar Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+

CVE-2021-24488
Post Grid Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2021 CWE-79 1 PoC

The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

CVE-2015-9308
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

CVE-2021-46780
Easy Google Maps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-24864
WP Cloudy, weather plugin Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue

CVE-2021-24521
Side Menu Lite – add sticky fixed buttons Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-89 1 PoC

The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

CVE-2023-3226
Popup Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2021-42740
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
9.0%
2021 1 PoC

The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject arbitrary commands. This is because the Windows drive letter regex character class is {A-z] instead of the correct {A-Za-z]. Several shell metacharacters exist in the space between capital letter Z and lower case letter a, such as the backtick character.

CVE-2021-24729
Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.

CVE-2015-5227
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.0%
2015 1 PoC

The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.

CVE-2023-1893
Login Configurator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2023 2 PoCs

The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.