11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2018-1002004
Arigato Autoresponder and Newsletter Web Windows
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

CVE-2019-13404
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or choose a different directory, because backwards compatibility requires that C:\Python27 remain the default for 2.7.x

CVE-2018-8134
Windows Server 2012 R2 Web Windows
N/A
UNKNOWN
EPSS
9.9%
2018 1 PoC

An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

CVE-2023-5210
AMP+ Plus Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2018-1038
Windows Windows
N/A
UNKNOWN
EPSS
61.3%
2018 2 PoCs

The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability."

CVE-2019-15820
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.

CVE-2015-1436
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in the Easing Slider plugin before 2.2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the edit parameter in the (1) easingslider_manage_customizations or (2) easingslider_edit_sliders page to wp-admin/admin.php.

CVE-2004-1244
Software Genérico Windows
N/A
UNKNOWN
EPSS
42.5%
2004 1 PoC

Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

CVE-2004-0897
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.5%
2004 1 PoC

The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

CVE-2014-8955
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.

CVE-2015-3088
Software Genérico Windows
N/A
UNKNOWN
EPSS
79.5%
2015 1 PoC

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2004-1361
Software Genérico Windows
N/A
UNKNOWN
EPSS
29.1%
2004 1 PoC

Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.

CVE-2004-0571
Software Genérico Windows
N/A
UNKNOWN
EPSS
25.8%
2004 1 PoC

Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.

CVE-2004-0201
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.7%
2004 1 PoC

Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.

CVE-2004-0211
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.9%
2004 2 PoCs

The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.

CVE-2004-1305
Software Genérico Windows
N/A
UNKNOWN
EPSS
78.5%
2004 3 PoCs

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.

CVE-2004-0117
Software Genérico Windows
N/A
UNKNOWN
EPSS
52.5%
2004 3 PoCs

Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

CVE-2004-0839
Software Genérico Windows
N/A
UNKNOWN
EPSS
42.0%
2004 2 PoCs

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

CVE-2015-9445
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.

CVE-2023-5140
Bonus for Woo Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.