11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2017-18556
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.

CVE-2017-0045
Windows DVD Maker Web Windows
N/A
UNKNOWN
EPSS
3.6%
2017 2 PoCs

Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."

CVE-2007-0199
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
1.5%
2007 1 PoC

The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."

CVE-2014-1734
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2014 1 PoC

Multiple unspecified vulnerabilities in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVE-2015-4139
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the s4w-more parameter to wp-admin/options-general.php.

CVE-2017-17092
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2017 0 PoCs

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVE-2017-0282
Uniscribe Windows
N/A
UNKNOWN
EPSS
13.0%
2017 1 PoC

Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0284, CVE-2017-0285, and CVE-2017-8534.

CVE-2017-18566
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.

CVE-2017-18596
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2017 1 PoC

The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.

CVE-2023-2326
Gravity Forms Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVE-2017-18010
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 2 PoCs

The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.

CVE-2017-7049
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
4.8%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-14685
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xps_load_links_in_glyphs in xps/xps-link.c does not verify that an xps font could be loaded.

CVE-2017-18501
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2017 0 PoCs

The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues.

CVE-2015-5560
Software Genérico Windows
N/A
UNKNOWN
EPSS
53.1%
2015 3 PoCs

Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2017-8479
Microsoft Windows Windows
N/A
UNKNOWN
EPSS
6.4%
2017 1 PoC

The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8492, CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8481, CVE-2017-8478, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-030

CVE-2017-10740
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlRbInsertNodeEx+0x000000000000002d."

CVE-2017-11914
ChakraCore, Microsoft Edge Windows
N/A
UNKNOWN
EPSS
73.4%
2017 1 PoC

ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11916, CVE-2017-

CVE-2017-14766
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2017 2 PoCs

The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.

CVE-2017-1002027
rk-responsive-contact-form Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2017 1 PoC

Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.