11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-24960
WordPress File Upload Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-434 2 PoCs

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks

CVE-2021-24246
Workscout Core Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues

CVE-2021-24758
Email Log Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections

CVE-2021-24447
WP Image Zoom Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-22 1 PoC

The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard

CVE-2021-24956
Blog2Social: Social Media Auto Post & Scheduler Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2021 CWE-79 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2014-8359
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.1%
2014 2 PoCs

Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll in the Mobile Partner directory.

CVE-2015-3080
Software Genérico Windows
N/A
UNKNOWN
EPSS
67.8%
2015 1 PoC

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2021-24819
Page/Post Content Shortcode Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.

CVE-2021-24812
BetterLinks – Shorten, Track and Manage any URL Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.

CVE-2021-24336
FlightLog Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users

CVE-2021-30605
Chrome Windows
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.

CVE-2021-24122
Apache Tomcat Web Windows
N/A
UNKNOWN
EPSS
59.8%
2021 CWE-200 1 PoC

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.

CVE-2015-8440
Software Genérico Windows
N/A
UNKNOWN
EPSS
6.0%
2015 3 PoCs

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-8409 and CVE-2015-8453.

CVE-2021-24125
Contact Form Submissions Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+)

CVE-2021-24384
JoomSport – for Sports: Team & League, Football, Hockey & more Web Windows
N/A
UNKNOWN
EPSS
4.5%
2021 CWE-502 1 PoC

The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this, other installed plugins could, which might lead to more severe issues such as RCE

CVE-2021-33851
WordPress Customize Login Image Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2021 CWE-79 1 PoC

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.

CVE-2021-24389
WP Foodbakery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.9%
2021 CWE-79 1 PoC

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2021-24989
Accept Donations with PayPal Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

CVE-2021-24316
Mediumish Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
57.4%
2021 CWE-79 2 PoCs

The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

CVE-2021-24630
Schreikasten Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 2 PoCs

The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQL statements in the comments dashboard from various actions, leading to authenticated SQL Injections which can be exploited by users as low as author