11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2017-7064
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
3.3%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

CVE-2017-14530
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.

CVE-2017-0055
IIS Server Web Windows
N/A
UNKNOWN
EPSS
1.4%
2017 1 PoC

Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability."

CVE-2017-4916
Workstation Pro/Player Windows
N/A
UNKNOWN
EPSS
9.5%
2017 1 PoC

VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.

CVE-2015-1204
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fs[resource] parameter in the wp-slim-view-2 page to wp-admin/admin.php.

CVE-2017-12551
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-20008
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin Web Windows
N/A
UNKNOWN
EPSS
0.4%
2017 CWE-79 1 PoC

The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2017-0121
Windows Uniscribe Windows
N/A
UNKNOWN
EPSS
13.0%
2017 1 PoC

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0122, CVE-2017-0123, CVE-2017-

CVE-2017-1000227
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 2 PoCs

Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can

CVE-2017-6104
Wordpress Plugin Mobile App Native 3.0 Web Windows
N/A
UNKNOWN
EPSS
38.6%
2017 2 PoCs

Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

CVE-2017-11907
Internet Explorer Windows
N/A
UNKNOWN
EPSS
76.2%
2017 2 PoCs

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11908, CVE-2017-1190

CVE-2017-1002000
mobile-friendly-app-builder-by-easytouch Web Windows
N/A
UNKNOWN
EPSS
64.3%
2017 1 PoC

Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.

CVE-2014-5460
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
64.7%
2014 5 PoCs

Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.

CVE-2015-2315
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
7.8%
2015 3 PoCs

Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.

CVE-2017-8404
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
24.5%
2017 1 PoC

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the POST parameters passed in this request (to test if email credentials and hostname sent to the device work properly) result in being passed as commands to a "system" API in the function and thus result in command injection on the device. If the firmware version is dissected using binwalk tool, we obtain a cramfs-root archive which contains the filesystem set up on the device that contains all the binaries. Th

CVE-2017-16744
Niagara AX Framework and Niagara 4 Framework Windows
N/A
UNKNOWN
EPSS
19.6%
2017 CWE-22 1 PoC

A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials.

CVE-2017-9418
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2017 2 PoCs

SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php.

CVE-2017-1092
Informix Servers Windows
N/A
UNKNOWN
EPSS
81.6%
2017 2 PoCs

IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X-Force ID: 120390.

CVE-2017-11893
ChakraCore, Microsoft Edge Windows
N/A
UNKNOWN
EPSS
74.0%
2017 1 PoC

ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-1191

CVE-2017-3528
Applications Framework Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
43.2%
2017 2 PoCs

Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks