11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2015-9421
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.

CVE-2017-16955
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2017 2 PoCs

SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.php.

CVE-2017-9287
Software Genérico Windows
N/A
UNKNOWN
EPSS
26.5%
2017 2 PoCs

servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.

CVE-2017-0135
Edge Windows
N/A
UNKNOWN
EPSS
22.5%
2017 1 PoC

Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.

CVE-2017-8538
Malware Protection Engine Windows
N/A
UNKNOWN
EPSS
62.6%
2017 1 PoC

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541.

CVE-2017-14313
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.3%
2017 1 PoC

The shibboleth_login_form function in shibboleth.php in the Shibboleth plugin before 1.8 for WordPress is prone to an XSS vulnerability due to improper use of add_query_arg().

CVE-2017-12548
System Management Homepage for Windows and Linux Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-2480
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
19.1%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

CVE-2017-0038
Windows Graphics Component Windows
N/A
UNKNOWN
EPSS
80.5%
2017 3 PoCs

gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.

CVE-2015-2572
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.6%
2015 3 PoCs

Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.

CVE-2017-9603
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.3%
2017 2 PoCs

SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.

CVE-2017-1000224
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin

CVE-2017-18585
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2017 1 PoC

The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.

CVE-2017-14091
Trend Micro ScanMail for Exchange Windows
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploited to overwrite sensitive files in the ScanMail for Exchange directory.

CVE-2017-0341
GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial of service or potential escalation of privileges.

CVE-2017-8484
Microsoft Windows Windows
N/A
UNKNOWN
EPSS
14.8%
2017 1 PoC

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8470, CVE-2017-8471, CVE-2017-8472, CVE-2017-8473, CVE-2017-8475, and CVE-2017-8477.

CVE-2017-17780
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and WP e-Commerce - Clockwork SMS 2.0.5.

CVE-2017-5612
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.5%
2017 1 PoC

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

CVE-2014-6412
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.4%
2014 2 PoCs

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

CVE-2015-1211
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.8%
2015 1 PoC

The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.