11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2017-16758
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 2 PoCs

Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "access_token" parameter.

CVE-2019-1477
Windows Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers, aka 'Windows Printer Service Elevation of Privilege Vulnerability'.

CVE-2020-9457
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.

CVE-2023-2495
Greeklish-permalink Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF.

CVE-2019-15896
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
3.7%
2019 2 PoCs

An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.

CVE-2015-2433
Software Genérico Windows
N/A
UNKNOWN
EPSS
17.6%
2015 1 PoC

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."

CVE-2017-15812
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel.

CVE-2017-0349
GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is not correctly validated before it is dereferenced for a write operation, may lead to denial of service or potential escalation of privileges.

CVE-2017-5942
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

An issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected XSS. This would allow you to execute JavaScript in the context of the user receiving the mail.

CVE-2017-18516
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.

CVE-2017-7117
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
9.1%
2017 2 PoCs

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-14184
FortiClient for Windows Networking Windows
N/A
UNKNOWN
EPSS
1.6%
2017 1 PoC

An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.

CVE-2015-2554
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.5%
2015 1 PoC

The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability."

CVE-2017-15134
389-ds-base Windows
N/A
UNKNOWN
EPSS
5.7%
2017 CWE-120 1 PoC

A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.

CVE-2017-11802
ChakraCore, Microsoft Edge Windows
N/A
UNKNOWN
EPSS
78.7%
2017 1 PoC

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and

CVE-2017-6096
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
3.4%
2017 2 PoCs

A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.

CVE-2017-8295
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
77.1%
2017 5 PoCs

WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the reset key to a mailbox on an attacker-controlled SMTP server. This is related to problematic use of the SERVER_NAME variable in wp-includes/pluggable.php in conjunction with the PHP mail function. Exploitation is not achievable in all cases because it requires at least one of the fol

CVE-2023-4808
WP Post Popup Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2017-0323
GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.

CVE-2017-8465
Microsoft Windows Windows
N/A
UNKNOWN
EPSS
7.0%
2017 1 PoC

Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to run processes in an elevated context when the Windows kernel improperly handles objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-8468.