1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-6732
Ultimate Maps by Supsystic Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-1025
Simple File List Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-6046
EventON Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.

CVE-2023-0892
BizLibrary Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1323
Easy Forms for Mailchimp Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-6005
EventON Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5137
Simply Excerpts Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

CVE-2023-3344
Auto Location for WP Job Manager via Google Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Auto Location for WP Job Manager via Google WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1525
Site Reviews Web Windows
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-6163
WP Crowdfunding Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0157
All-In-One Security (AIOS) Web Windows
4.8
MEDIUM
EPSS
25.1%
2023 2 PoCs

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this page.

CVE-2023-5943
Wp-Adv-Quiz Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2023-32019
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
2.8%
2023 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2023-21766
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
6.4%
2023 CWE-591 1 PoC

Windows Overlay Filter Information Disclosure Vulnerability

CVE-2023-0192
vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
4.7
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and information disclosure.

CVE-2023-1112
Drag and Drop Multiple File Upload Contact Form 7 Web Windows
4.7
MEDIUM
EPSS
31.8%
2023 CWE-23 1 PoC

A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222072.

CVE-2023-7236
Backup Bolt Web Windows
4.7
MEDIUM
EPSS
0.4%
2023 1 PoC

The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.

CVE-2023-28345
Software Genérico Web Windows
4.6
MEDIUM
EPSS
0.0%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console can open a web browser, navigate to the affected endpoint and obtain the teacher's password. This enables them to log into the Teacher Console and begin trivially attacking student machines.

CVE-2023-1374
Solidres – Hotel booking plugin for WordPress Web Windows
4.4
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

The Solidres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'currency_name' parameter in versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-5621
Thumbnail Slider With Lightbox Web Windows
4.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.