11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2014-8955
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.

CVE-2015-3088
Software Genérico Windows
N/A
UNKNOWN
EPSS
79.5%
2015 1 PoC

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2004-1361
Software Genérico Windows
N/A
UNKNOWN
EPSS
29.1%
2004 1 PoC

Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.

CVE-2004-0571
Software Genérico Windows
N/A
UNKNOWN
EPSS
25.8%
2004 1 PoC

Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.

CVE-2018-16283
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2018 4 PoCs

The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.

CVE-2018-5652
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_end parameter.

CVE-2013-5961
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
7.0%
2013 1 PoC

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

CVE-2004-0201
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.7%
2004 1 PoC

Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.

CVE-2004-0211
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.9%
2004 2 PoCs

The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.

CVE-2004-1305
Software Genérico Windows
N/A
UNKNOWN
EPSS
78.5%
2004 3 PoCs

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.

CVE-2004-0117
Software Genérico Windows
N/A
UNKNOWN
EPSS
52.5%
2004 3 PoCs

Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

CVE-2004-0839
Software Genérico Windows
N/A
UNKNOWN
EPSS
42.0%
2004 2 PoCs

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

CVE-2015-9445
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.

CVE-2023-5140
Bonus for Woo Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2004-0069
Software Genérico Windows
N/A
UNKNOWN
EPSS
8.3%
2004 2 PoCs

Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.

CVE-2004-2289
Software Genérico Windows
N/A
UNKNOWN
EPSS
12.1%
2004 2 PoCs

Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.

CVE-2004-0901
Software Genérico Windows
N/A
UNKNOWN
EPSS
36.2%
2004 1 PoC

Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.

CVE-2004-0727
Software Genérico Windows
N/A
UNKNOWN
EPSS
57.6%
2004 1 PoC

Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."

CVE-2023-4933
WP Job Openings Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

CVE-2004-0686
Software Genérico Windows
N/A
UNKNOWN
EPSS
11.6%
2004 1 PoC

Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.