11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2017-18564
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The sender plugin before 1.2.1 for WordPress has multiple XSS issues.

CVE-2007-1213
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.7%
2007 1 PoC

The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.

CVE-2014-8810
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
3.4%
2014 1 PoC

SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.

CVE-2015-5577
Software Genérico Windows
N/A
UNKNOWN
EPSS
4.3%
2015 3 PoCs

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.

CVE-2017-8485
Microsoft Windows Windows
N/A
UNKNOWN
EPSS
7.7%
2017 1 PoC

The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8492, CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8483, CVE-2017-8482, CVE-2017-8480, CVE-2017-8479, CVE-2017-8478, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-030

CVE-2017-7089
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
1.9%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.

CVE-2019-10866
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
13.5%
2019 2 PoCs

In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.

CVE-2014-1713
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.0%
2014 1 PoC

Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the document.location value.

CVE-2017-0058
Windows Windows
N/A
UNKNOWN
EPSS
16.5%
2017 1 PoC

A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability."

CVE-2017-11658
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
3.0%
2017 1 PoC

In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.%00.../ attack.

CVE-2017-15810
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2017 2 PoCs

The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.

CVE-2017-12553
System Management Homepage for Windows and Linux Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-0322
Windows GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a value passed from a user to the driver is not correctly validated and used as the index to an array, leading to denial of service or potential escalation of privileges.

CVE-2017-1002003
wp2android-turn-wp-site-into-android-app Web Windows
N/A
UNKNOWN
EPSS
47.7%
2017 2 PoCs

Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

CVE-2017-9420
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.

CVE-2017-6818
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
9.3%
2017 1 PoC

In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.

CVE-2017-8652
Microsoft Edge Windows
N/A
UNKNOWN
EPSS
61.7%
2017 1 PoC

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017-8662.

CVE-2023-38431
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-bounds read.

CVE-2017-4909
Workstation Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation bu

CVE-2017-14844
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2017 1 PoC

Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.