11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2014-2441
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.0%
2014 1 PoC

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.32, 4.2.24, and 4.3.10 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.

CVE-2015-9389
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.

CVE-2017-0090
Windows Uniscribe Windows
N/A
UNKNOWN
EPSS
24.0%
2017 1 PoC

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, and CVE-2017-0089.

CVE-2017-14843
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2017 1 PoC

Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.

CVE-2017-18565
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The updater plugin before 1.35 for WordPress has multiple XSS issues.

CVE-2017-11809
ChakraCore, Microsoft Edge Windows
N/A
UNKNOWN
EPSS
78.7%
2017 1 PoC

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and

CVE-2017-2414
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "DataAccess" component. It allows remote attackers to access Exchange traffic in opportunistic circumstances by leveraging a mistake in typing an e-mail address.

CVE-2017-14092
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.

CVE-2017-14725
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2017 1 PoC

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVE-2017-0092
Windows Uniscribe Windows
N/A
UNKNOWN
EPSS
9.7%
2017 1 PoC

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.

CVE-2015-9312
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2015 0 PoCs

The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.

CVE-2023-5991
Hotel Booking Lite Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2023 1 PoC

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

CVE-2017-5411
Firefox Windows
N/A
UNKNOWN
EPSS
0.7%
2017 2 PoCs

A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVE-2017-18598
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2017 1 PoC

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

CVE-2017-12547
System Management Homepage for Windows and Linux Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-12650
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2017 1 PoC

SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.

CVE-2023-5239
Security & Malware scan by CleanTalk Web Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.

CVE-2017-0290
Microsoft Malware Protection Engine Windows
N/A
UNKNOWN
EPSS
87.8%
2017 4 PoCs

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."

CVE-2017-7042
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
14.4%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-5493
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.7%
2017 1 PoC

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.