11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2015-1582
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Spider Facebook plugin before 1.0.11 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the appid parameter in a registration task to the default URI or remote administrators to inject arbitrary web script or HTML via the (2) asc_or_desc, (3) order_by, (4) page_number, (5) serch_or_not, or (6) search_events_by_title parameter in (a) the Spider_Facebook_manage page to wp-admin/admin.php or a (b) selectpagesforfacebook or (c) selectpostsforfacebook action to wp-admin/admin-ajax.php.

CVE-2021-24222
WP-Curriculo Vitae Free Web Windows
N/A
UNKNOWN
EPSS
5.7%
2021 CWE-434 1 PoC

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

CVE-2021-24387
WP Pro Real Estate 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.0%
2021 CWE-79 1 PoC

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

CVE-2021-24972
Pixel Cat – Conversion Pixel Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2013-0884
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly load Native Client (aka NaCl) code, which has unspecified impact and attack vectors.

CVE-2015-5151
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in the Slider Revolution (revslider) plugin 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the client_action parameter in a revslider_ajax_action action to wp-admin/admin-ajax.php.

CVE-2021-24353
Simple 301 Redirects by BetterLinks Web Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-862 1 PoC

The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.

CVE-2021-24749
URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.

CVE-2021-4208
ExportFeed: List WooCommerce Products on eBay Store Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using it in a SQL statement, leading to a SQL injection vulnerability exploitable by high privilege users

CVE-2015-2522
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
8.6%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content, aka "Microsoft SharePoint XSS Spoofing Vulnerability."

CVE-2021-24699
Easy Media Download Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

CVE-2021-24152
Popup Builder – Responsive WordPress Pop up – Subscription & Newsletter Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.

CVE-2021-24937
Asset CleanUp: Page Speed Booster Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24150
Like Button Rating ♥ LikeBtn Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
46.3%
2021 CWE-918 1 PoC

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

CVE-2007-1436
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.5%
2007 2 PoCs

Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring.

CVE-2007-3111
Software Genérico Windows
N/A
UNKNOWN
EPSS
51.3%
2007 1 PoC

Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.

CVE-2014-2550
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php.

CVE-2013-6010
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in the Comment Attachment plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Attachment field title."

CVE-2015-5553
Software Genérico Windows
N/A
UNKNOWN
EPSS
4.2%
2015 3 PoCs

Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5544, CVE-2015-5545, CVE-2015-5546, CVE-2015-5547, CVE-2015-5548, CVE-2015-5549, and CVE-2015-5552.

CVE-2023-4284
Post Timeline Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.1%
2023 1 PoC

The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin