11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-5669
NVIDIA GPU Graphics Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2019 2 PoCs

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape in which the software uses a sequential operation to read from or write to a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer, which may lead to denial of service or escalation of privileges.

CVE-2017-8487
Microsoft Windows Windows
N/A
UNKNOWN
EPSS
69.3%
2017 1 PoC

Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerability."

CVE-2017-1000219
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.3%
2017 1 PoC

npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user

CVE-2017-8411
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
10.4%
2017 1 PoC

An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the POST parameters passed in this request (to test if email credentials and hostname sent to the device work properly) result in being passed as commands to a "system" API in the function and thus result in command injection on the device. If the firmware version is dissected using binwalk tool, we obtain a cramfs-root archive which contains the filesystem set up on the device that contains all the binaries. Th

CVE-2016-4226
Software Genérico Windows
N/A
UNKNOWN
EPSS
75.3%
2016 2 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4222, CVE-2016-4227, CVE-2016-4228, CVE-2016-4229, CVE-2016-4230, CVE-2016-4231, and CVE-2016-4248.

CVE-2019-1096
Windows Windows
N/A
UNKNOWN
EPSS
34.6%
2019 1 PoC

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

CVE-2016-10873
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2016 1 PoC

The wp-database-backup plugin before 4.3.3 for WordPress has XSS.

CVE-2023-6272
tml-2fa Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

CVE-2017-0220
Microsoft Windows Windows
N/A
UNKNOWN
EPSS
4.1%
2017 1 PoC

The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0258, and CVE-2017-0259.

CVE-2017-17069
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched from a directory where an attacker has already created a Trojan horse dwmapi.dll file.

CVE-2015-5130
Software Genérico Windows
N/A
UNKNOWN
EPSS
53.0%
2015 4 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5559, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

CVE-2017-6817
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
6.1%
2017 1 PoC

In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.

CVE-2017-8492
Microsoft Windows Windows
N/A
UNKNOWN
EPSS
14.8%
2017 1 PoC

The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8480, CVE-2017-8479, CVE-2017-8478, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-030

CVE-2017-1002002
webapp-builder Web Windows
N/A
UNKNOWN
EPSS
51.2%
2017 2 PoCs

Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/

CVE-2017-17451
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.3%
2017 2 PoCs

The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.

CVE-2017-8740
Microsoft Edge Windows
N/A
UNKNOWN
EPSS
78.2%
2017 1 PoC

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.

CVE-2017-11906
Internet Explorer Windows
N/A
UNKNOWN
EPSS
58.9%
2017 1 PoC

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11887 and CVE-2017-11919.

CVE-2017-18527
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.

CVE-2017-7040
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
3.5%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2007-1437
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution.