1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-0263
WP Yelp Review Slider Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-5884
Word Balloon Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

CVE-2023-20567
Radeon™ RX 5000/6000/7000 Series Graphics Cards Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

CVE-2023-38429
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.

CVE-2023-5990
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not have CSRF checks on some of its form actions such as deletion and duplication, which could allow attackers to make logged in admin perform such actions via CSRF attacks

CVE-2023-6295
SiteOrigin Widgets Bundle Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

CVE-2023-4922
wpb-show-core Web Windows
N/A
UNKNOWN
EPSS
26.4%
2023 1 PoC

The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.

CVE-2023-0231
ShopLentor Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2636
AN_GradeBook Web Database Windows
N/A
UNKNOWN
EPSS
4.6%
2023 3 PoCs

The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber

CVE-2023-5939
rtMedia for WordPress, BuddyPress and bbPress Web Windows
N/A
UNKNOWN
EPSS
3.7%
2023 1 PoC

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

CVE-2023-0099
Simple URLs Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.1%
2023 3 PoCs

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-5210
AMP+ Plus Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-26326
BuddyForms WordPress Plugin Web Windows
N/A
UNKNOWN
EPSS
45.0%
2023 3 PoCs

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.

CVE-2023-0076
Download Attachments Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-4799
Magic Embeds Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2718
Contact Form Email Web Windows
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.

CVE-2023-28660
Events Made Easy WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.

CVE-2023-0538
Campaign URL Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-5958
POST SMTP Mailer Web Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

CVE-2023-3356
Subscribers Text Counter Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping