1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-29804
Software Genérico Windows
8.8
HIGH
EPSS
19.9%
2023 1 PoC

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.

CVE-2023-28349
Software Genérico Windows
8.8
HIGH
EPSS
0.7%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. Connected Student Consoles can be compelled to write arbitrary files to arbitrary locations on disk with NT AUTHORITY/SYSTEM level permissions, enabling remote code execution.

CVE-2023-21742
Microsoft SharePoint Enterprise Server 2016 Windows
8.8
HIGH
EPSS
16.5%
2023 CWE-284 1 PoC

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2023-0259
WP Google Review Slider Web Database Windows
8.8
HIGH
EPSS
0.5%
2023 1 PoC

The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-21707
Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.8
HIGH
EPSS
72.0%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-2288
Otter Web Windows
8.8
HIGH
EPSS
14.1%
2023 1 PoC

The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.

CVE-2023-0340
Custom Content Shortcode Web Windows
8.8
HIGH
EPSS
1.2%
2023 1 PoC

The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.

CVE-2023-3124
Elementor Website Builder Pro Web Windows
8.8
HIGH
EPSS
26.0%
2023 CWE-862 1 PoC

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

CVE-2023-35080
Secure Access Client Windows
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.

CVE-2023-35674
🔥 KEV Android Windows
8.8
HIGH
EPSS
0.1%
2023 2 PoCs

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-39211
Zoom Desktop Client for Windows and Zoom Rooms for Windows Windows
8.8
HIGH
EPSS
0.0%
2023 CWE-347 1 PoC

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

CVE-2023-2440
UserPro - Community and User Profile WordPress Plugin Web Windows
8.8
HIGH
EPSS
0.1%
2023 CWE-352 1 PoC

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing nonce validation in the 'admin_page', 'userpro_verify_user' and 'verifyUnverifyAllUsers' functions. This makes it possible for unauthenticated attackers to modify the role of verified users to elevate verified user privileges to that of any user such as 'administrator' via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-5412
Image horizontal reel scroll slideshow Web Database Windows
8.8
HIGH
EPSS
9.8%
2023 CWE-89 1 PoC

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-51772
Software Genérico Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click on the Help icon, observe that there is a browser window for the One Identity website, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\SYSTEM.

CVE-2023-6009
UserPro - Community and User Profile WordPress Plugin Web Windows
8.8
HIGH
EPSS
0.2%
2023 CWE-266 2 PoCs

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.

CVE-2023-1938
WP Fastest Cache Web Windows
8.8
HIGH
EPSS
8.2%
2023 1 PoC

The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue

CVE-2023-4643
Enable Media Replace Web Windows
8.8
HIGH
EPSS
0.4%
2023 1 PoC

The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog

CVE-2023-5311
WP EXtra – One Click Optimize Web Windows
8.8
HIGH
EPSS
6.6%
2023 CWE-862 1 PoC

The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the .htaccess files located in a site's root directory or /wp-content and /wp-includes folders and achieve remote code execution. CVE-2023-46623 appears to be a duplicate of this issue.

CVE-2023-38043
Secure Access Client Windows Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.

CVE-2023-0820
User Role by BestWebSoft Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.