11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-6634
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Windows ⚡ nuclei
8.1
HIGH
EPSS
91.3%
2023 CWE-88 2 PoCs

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

CVE-2024-21407
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
6.3%
2024 CWE-416 1 PoC

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2008-1083
Software Genérico Windows
8.1
HIGH
EPSS
52.2%
2008 3 PoCs

Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."

CVE-2023-28244
Windows Server 2019 Windows
8.1
HIGH
EPSS
6.0%
2023 CWE-327 1 PoC

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-27480
Windows Server 2012 Windows
8.1
HIGH
EPSS
0.8%
2025 CWE-416 2 PoCs

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

CVE-2021-21389
BuddyPress Web Windows ⚡ nuclei
8.1
HIGH
EPSS
93.3%
2021 CWE-863 2 PoCs

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

CVE-2023-29325
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
22.1%
2023 CWE-416 2 PoCs

Windows OLE Remote Code Execution Vulnerability

CVE-2020-36659
Software Genérico Web Windows
8.1
HIGH
EPSS
0.3%
2020 1 PoC

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.

CVE-2025-24035
Windows 10 Version 1507 Windows
8.1
HIGH
EPSS
0.1%
2025 CWE-591 1 PoC

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVE-2023-5905
DeMomentSomTres WordPress Export Posts With Images Web Windows
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.

CVE-2009-1529
Software Genérico Windows
8.1
HIGH
EPSS
59.9%
2009 1 PoC

Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by calling the setCapture method on a collection of crafted objects, aka "Uninitialized Memory Corruption Vulnerability."

CVE-2009-2502
Software Genérico Database Windows
8.1
HIGH
EPSS
43.7%
2009 1 PoC

Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Vi

CVE-2025-4336
eMagicOne Store Manager for WooCommerce Web Windows
8.1
HIGH
EPSS
1.9%
2025 CWE-434 2 PoCs

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This is only exploitable by unauthenticated attackers in default configurations where the the default password is left as 1:1, or where the attacker gains access to the credentials.

CVE-2024-0399
WooCommerce Customers Manager Web Database Windows
8.1
HIGH
EPSS
2.0%
2024 2 PoCs

The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.

CVE-2016-2123
samba Windows
8.1
HIGH
EPSS
0.9%
2016 CWE-122 1 PoC

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

CVE-2024-11848
NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization Web Windows
8.1
HIGH
EPSS
5.6%
2024 CWE-862 1 PoC

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options to a fixed value of '1' which can activate certain options (e.g., enable user registration) or modify certain options in a way that leads to a denial of service condition.

CVE-2025-2594
User Registration & Membership Web Windows
8.1
HIGH
EPSS
7.4%
2025 2 PoCs

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

CVE-2024-3183
Software Genérico Windows
8.1
HIGH
EPSS
21.2%
2024 CWE-916 1 PoC

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal key directly. For user principals, this key is a hash of a public per-principal randomly-generated salt and the user’s password. If a principal is compromised it means the attacker would be able to retrieve tickets encrypted to any principal, all of them being encrypted by their own key directly. By taking these tickets

CVE-2009-0551
Software Genérico Web Windows
8.1
HIGH
EPSS
52.3%
2009 1 PoC

Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."

CVE-2017-12615
🔥 KEV Apache Tomcat Web Windows ⚡ nuclei
8.1
HIGH
EPSS
94.2%
2017 14 PoCs

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.