11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2017-18599
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter.

CVE-2017-18500
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2017 0 PoCs

The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.

CVE-2017-8684
Windows GDI+ Windows
N/A
UNKNOWN
EPSS
26.9%
2017 1 PoC

Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8685 and CVE-2017-8688.

CVE-2017-11332
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.6%
2017 2 PoCs

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

CVE-2014-9398
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2014 1 PoC

Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the mashtlb_twitter_username parameter in the twitter-liveblog.php page to wp-admin/options-general.php.

CVE-2015-8430
Software Genérico Windows
N/A
UNKNOWN
EPSS
77.9%
2015 4 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015

CVE-2017-11870
ChakraCore, Microsoft Edge Windows
N/A
UNKNOWN
EPSS
80.4%
2017 1 PoC

ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11871, and CVE-2017-11873.

CVE-2017-12550
System Management Homepage for Windows and Linux Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-5031
Firefox ESR Windows
N/A
UNKNOWN
EPSS
0.8%
2017 1 PoC

A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVE-2017-17043
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.0%
2017 2 PoCs

The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php is not filtered correctly.

CVE-2017-0285
Uniscribe Windows
N/A
UNKNOWN
EPSS
11.4%
2017 1 PoC

Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, and Microsoft Office Word Viewer allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0282, CVE-2017-0284, and CVE-2017-8534.

CVE-2017-0319
Windows GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.

CVE-2017-8734
Microsoft Edge Windows
N/A
UNKNOWN
EPSS
70.0%
2017 1 PoC

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8751, and CVE-2017-11766.

CVE-2017-18610
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id parameter.

CVE-2015-9440
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.

CVE-2017-18551
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds write in the function i2c_smbus_xfer_emulated.

CVE-2017-8644
Microsoft Edge Windows
N/A
UNKNOWN
EPSS
44.4%
2017 1 PoC

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8652 and CVE-2017-8662.

CVE-2017-18607
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

The avada theme before 5.1.5 for WordPress has CSRF.

CVE-2017-0344
GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape may allow users to gain access to arbitrary physical memory, leading to escalation of privileges.

CVE-2023-0439
NEX-Forms Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.