11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-4349
Process Steps Template Designer Web Windows
8.8
HIGH
EPSS
0.4%
2021 CWE-352 1 PoC

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-9216
StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More Web Windows
8.8
HIGH
EPSS
0.5%
2025 CWE-434 2 PoCs

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2018-3844
Perceptive Document Filters Windows
8.8
HIGH
EPSS
0.1%
2018 1 PoC

In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, a crafted DOCX document can lead to a use-after-free resulting in direct code execution.

CVE-2018-3851
Perceptive Document Filters Windows
8.8
HIGH
EPSS
1.1%
2018 1 PoC

In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, an exploitable stack-based buffer overflow exists in the DOC-to-HTML conversion functionality of the Hyland Perceptive Document Filters version 11.4.0.2647. A crafted .doc document can lead to a stack-based buffer, resulting in direct code execution.

CVE-2017-0144
🔥 KEV Windows SMB Windows
8.8
HIGH
EPSS
94.3%
2017 10 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CVE-2017-0143
🔥 KEV Windows SMB Windows
8.8
HIGH
EPSS
94.0%
2017 18 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CVE-2024-6974
SDP Client Windows
8.8
HIGH
EPSS
0.1%
2024 CWE-426 1 PoC

Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

CVE-2026-21513
🔥 KEV Windows 10 Version 1607 Windows
8.8
HIGH
EPSS
28.1%
2026 CWE-693 2 PoCs

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

CVE-2021-24566
FOX Web Windows
8.8
HIGH
EPSS
1.8%
2021 1 PoC

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

CVE-2026-30783
RustDesk Client Web Windows
8.8
HIGH
EPSS
0.1%
2026 CWE-602 1 PoC

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_mediator.Rs, src/hbbs_http/sync.Rs and program routines API sync loop, api-server config handling. This issue affects RustDesk Client: through 1.4.5.

CVE-2024-3807
Porto Web Windows
8.8
HIGH
EPSS
5.5%
2024 CWE-98 1 PoC

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included. This was partially patched in version 7.1.0

CVE-2021-31181
Microsoft SharePoint Enterprise Server 2016 Windows
8.8
HIGH
EPSS
40.7%
2021 1 PoC

Microsoft SharePoint Remote Code Execution Vulnerability

CVE-2025-1304
NewsBlogger Web Windows
8.8
HIGH
EPSS
1.5%
2025 CWE-862 1 PoC

The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2018-3845
Perceptive Document Filters Windows
8.8
HIGH
EPSS
0.5%
2018 1 PoC

In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, a crafted OpenDocument document can lead to a SkCanvas object double free resulting in direct code execution.

CVE-2025-66428
Software Genérico Web Windows
8.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.

CVE-2023-0255
Enable Media Replace Web Windows
8.8
HIGH
EPSS
1.4%
2023 2 PoCs

The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

CVE-2018-3998
Atlantis Word Processor Windows
8.8
HIGH
EPSS
0.3%
2018 1 PoC

An exploitable heap-based buffer overflow vulnerability exists in the Windows enhanced metafile parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause an undersized allocation, resulting in an overflow when the application tries to copy data into it. An attacker must convince a victim to open a document in order to trigger this vulnerability.

CVE-2008-0015
🔥 KEV Software Genérico Windows
8.8
HIGH
EPSS
81.6%
2008 2 PoCs

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."

CVE-2009-1532
Software Genérico Windows
8.8
HIGH
EPSS
59.4%
2009 1 PoC

Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, SP1, and SP2; and 8 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via "malformed row property references" that trigger an access of an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Objects Memory Corruption Vulnerability" or "HTML Object Memory Corruption Vulnerability."

CVE-2023-4536
My Account Page Editor Web Windows
8.8
HIGH
EPSS
0.6%
2023 1 PoC

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE