11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-15832
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.

CVE-2017-1002022
surveys Web Database Windows
N/A
UNKNOWN
EPSS
10.9%
2017 1 PoC

Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query.

CVE-2017-0086
Windows Uniscribe Windows
N/A
UNKNOWN
EPSS
24.0%
2017 1 PoC

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0083, CVE-2017-0084, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, and CVE-2017-0090.

CVE-2018-1002000
Arigato Autoresponder and Newsletter Web Database Windows
N/A
UNKNOWN
EPSS
4.1%
2018 1 PoC

There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.

CVE-2019-19916
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could result in script running where CSP should have blocked it, allowing for cross-site scripting (XSS) and other attacks when the product renders the content as HTML. Remediating this would also need to consider the polyglot case, e.g., a file that is a valid GIF image and also valid JavaScript.

CVE-2015-9500
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.

CVE-2023-44469
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.

CVE-2017-8683
Windows graphics Windows
N/A
UNKNOWN
EPSS
18.2%
2017 1 PoC

Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8682.

CVE-2017-14947
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at mupdfnet64!mIncrementalSaveFile+0x0000000000193359."

CVE-2017-9288
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2017 2 PoCs

The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter).

CVE-2017-18540
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.

CVE-2015-1614
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) image_metadata_cruncher[alt] or (2) image_metadata_cruncher[caption] parameter in an update action in the image_metadata_cruncher_title page to wp-admin/options.php or (3) custom image meta tag to the image metadata cruncher page.

CVE-2017-8751
Microsoft Edge Windows
N/A
UNKNOWN
EPSS
54.0%
2017 1 PoC

Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8734, and CVE-2017-11766.

CVE-2017-9419
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.

CVE-2004-1317
Software Genérico Windows
N/A
UNKNOWN
EPSS
77.8%
2004 3 PoCs

Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.

CVE-2004-0568
Software Genérico Windows
N/A
UNKNOWN
EPSS
26.9%
2004 1 PoC

HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.

CVE-2004-0123
Software Genérico Windows
N/A
UNKNOWN
EPSS
59.1%
2004 1 PoC

Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVE-2004-1244
Software Genérico Windows
N/A
UNKNOWN
EPSS
42.5%
2004 1 PoC

Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

CVE-2004-0897
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.5%
2004 1 PoC

The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

CVE-2014-8955
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.