11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-21389
BuddyPress Web Windows ⚡ nuclei
8.1
HIGH
EPSS
93.3%
2021 CWE-863 2 PoCs

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

CVE-2017-0037
🔥 KEV Internet Browser Web Windows
8.1
HIGH
EPSS
89.1%
2017 5 PoCs

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

CVE-2025-3515
Drag and Drop Multiple File Upload for Contact Form 7 Web Windows ⚡ nuclei
8.1
HIGH
EPSS
4.6%
2025 CWE-434 6 PoCs

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other dangerous file types on the affected site's server, which may make remote code execution possible on the servers that are configured to handle .phar files as executable PHP scripts, particularly in default Apache+mod_php configurations where the file extension is not strictly vali

CVE-2017-0148
🔥 KEV Windows SMB Windows
8.1
HIGH
EPSS
94.1%
2017 5 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.

CVE-2024-13800
ConvertPlus Web Windows
8.1
HIGH
EPSS
0.1%
2024 CWE-862 1 PoC

The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to '1' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration.

CVE-2017-12615
🔥 KEV Apache Tomcat Web Windows ⚡ nuclei
8.1
HIGH
EPSS
94.2%
2017 14 PoCs

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2022-23270
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
48.4%
2022 1 PoC

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

CVE-2022-21936
Software Genérico Windows
8.1
HIGH
EPSS
0.2%
2022 1 PoC

On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.

CVE-2023-5815
Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News Web Windows ⚡ nuclei
8.1
HIGH
EPSS
49.2%
2023 CWE-98 1 PoC

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including, 3.4.1 via the bdp_get_more_post function hooked via a nopriv AJAX. This is due to function utilizing an unsafe extract() method to extract values from the POST variable and passing that input to the include() function. This makes it possible for unauthenticated attackers to include arbitrary PHP files and achieve remote code ex

CVE-2025-21224
Windows 10 Version 21H2 Windows
8.1
HIGH
EPSS
0.5%
2025 CWE-591 2 PoCs

Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

CVE-2022-2431
Download Manager Web Windows
8.1
HIGH
EPSS
17.1%
2022 CWE-73 1 PoC

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it possible for contributor level users and above to supply an arbitrary file path via the 'file[files]' parameter when creating a download post and once the user deletes the post the supplied arbitrary file will be deleted. This can be used by attackers to delete the /wp-config.php file w

CVE-2025-3102
OttoKit: All-in-One Automation Platform Web Windows ⚡ nuclei
8.1
HIGH
EPSS
87.8%
2025 CWE-697 10 PoCs

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVE-2024-7863
Favicon Generator (CLOSED) Web Windows
8.1
HIGH
EPSS
0.2%
2024 1 PoC

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server

CVE-2022-24545
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
4.1%
2022 1 PoC

Windows Kerberos Remote Code Execution Vulnerability

CVE-2022-47943
Software Genérico Windows
8.1
HIGH
EPSS
1.3%
2022 1 PoC

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case.

CVE-2020-36659
Software Genérico Web Windows
8.1
HIGH
EPSS
0.3%
2020 1 PoC

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.

CVE-2025-14975
Custom Login Page Customizer Web Windows
8.1
HIGH
EPSS
0.0%
2025 1 PoC

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

CVE-2025-8592
Inspiro Web Windows
8.1
HIGH
EPSS
0.0%
2025 CWE-352 1 PoC

The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on the inspiro_install_plugin() function. This makes it possible for unauthenticated attackers to install plugins from the repository via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-32710
Windows Server 2008 R2 Service Pack 1 Windows
8.1
HIGH
EPSS
0.7%
2025 CWE-416 1 PoC

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.