1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-4318
Herd Effects Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

CVE-2023-2287
Orbit Fox by ThemeIsle Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

CVE-2023-1939
Remote Desktop Manager Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

No access control for the OTP key   on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.

CVE-2023-0505
Ever Compare Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0498
WP Education Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-1088
WP Plugin Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-34121
Zoom for Windows Windows
4.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.

CVE-2023-5359
W3 Total Cache Web Windows
3.7
LOW
EPSS
2.4%
2023 CWE-200 1 PoC

The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.

CVE-2023-7297
TwitterPosts Web Windows
3.5
LOW
EPSS
0.1%
2023 1 PoC

The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-4973
LMS Windows ⚡ nuclei
3.5
LOW
EPSS
5.0%
2023 CWE-79 2 PoCs

A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument searched_word/searched_tution_class_type[]/searched_price_type[]/searched_duration[] leads to cross site scripting. The attack can be launched remotely. The identifier VDB-239749 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-0429
Watu Quiz Web Windows
3.5
LOW
EPSS
0.2%
2023 1 PoC

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-3666
Sticky Side Buttons Web Windows
3.3
LOW
EPSS
0.0%
2023 1 PoC

The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-28351
Software Genérico Windows
3.3
LOW
EPSS
0.0%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student application installed is logged to a world-readable directory. A local attacker can trivially extract these cleartext keystrokes, potentially enabling them to obtain PII and/or to compromise personal accounts owned by the victim.

CVE-2023-39202
Zoom Rooms Client for Windows and Zoom VDI Client Windows
3.1
LOW
EPSS
0.0%
2023 CWE-426 1 PoC

Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

CVE-2023-2282
Remote Desktop Manager Windows
3.1
LOW
EPSS
0.3%
2023 1 PoC

Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.

CVE-2023-31028
nvJPEG2000 Library Windows
2.8
LOW
EPSS
0.0%
2023 CWE-20 1 PoC

NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.

CVE-2023-28602
Zoom for Windows Client Windows
2.8
LOW
EPSS
0.1%
2023 CWE-347 1 PoC

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

CVE-2023-2117
Image Optimizer by 10web Web Windows
2.7
LOW
EPSS
0.2%
2023 1 PoC

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

CVE-2023-4216
Orders Tracking for WooCommerce Web Windows
2.7
LOW
EPSS
0.1%
2023 1 PoC

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first line of the file.

CVE-2023-2252
Directorist Web Windows ⚡ nuclei
2.7
LOW
EPSS
7.8%
2023 1 PoC

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.