11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-28348
Software Genérico Windows
7.4
HIGH
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack on either a connected student or teacher, enabling them to intercept student keystrokes or modify executable files being sent from teachers to students.

CVE-2023-5527
Business Directory Plugin – Easy Listing Directories for WordPress Web Windows
7.4
HIGH
EPSS
0.5%
2023 CWE-1236 1 PoC

The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVE-2023-4136
CrafterCMS Web Windows ⚡ nuclei
7.4
HIGH
EPSS
24.9%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.

CVE-2023-34114
Zoom for Windows Client Windows
7.4
HIGH
EPSS
0.3%
2023 CWE-668 1 PoC

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2023-0824
User registration & user profile Web Windows
7.4
HIGH
EPSS
0.1%
2023 1 PoC

The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-28352
Software Genérico Windows
7.4
HIGH
EPSS
0.0%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can connect to and attack a Teacher Console even after Enhanced Security Mode has been enabled.

CVE-2023-52424
Software Genérico Windows
7.4
HIGH
EPSS
0.2%
2023 1 PoC

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.

CVE-2024-6492
Remote Desktop Manager Windows
7.4
HIGH
EPSS
0.6%
2024 1 PoC

Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.

CVE-2019-12098
Software Genérico Windows
7.4
HIGH
EPSS
2.8%
2019 1 PoC

In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.

CVE-2025-63946
Software Genérico Windows
7.4
HIGH
EPSS
0.0%
2025 1 PoC

A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

CVE-2025-59489
Unity Editor Windows
7.4
HIGH
EPSS
0.0%
2025 CWE-88 3 PoCs

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of

CVE-2020-35947
Software Genérico Web Windows
7.4
HIGH
EPSS
0.5%
2020 2 PoCs

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.

CVE-2020-36838
Facebook Chat Plugin – Live Chat Plugin for WordPress Web Windows
7.4
HIGH
EPSS
0.0%
2020 CWE-284 1 PoC

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site running the vulnerable plugin and engage in chats with site visitors on affected sites.

CVE-2020-7278
McAfee Endpoint Security (ENS) Networking Windows
7.4
HIGH
EPSS
0.2%
2020 CWE-284 1 PoC

Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.

CVE-2018-8581
🔥 KEV Microsoft Exchange Server Windows
7.4
HIGH
EPSS
91.5%
2018 2 PoCs

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

CVE-2022-1467
AVEVA InTouch Access Anywhere Windows
7.4
HIGH
EPSS
0.3%
2022 CWE-668 1 PoC

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVE-2026-6265
Cerberus FTP Server Windows
7.3
HIGH
EPSS
0.0%
2026 CWE-278 1 PoC

Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1

CVE-2023-34118
Zoom Rooms for Windows Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-250 1 PoC

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-41929
Software Genérico Windows
7.3
HIGH
EPSS
0.0%
2023 1 PoC

A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)

CVE-2023-31341
μProf Tool Windows
7.3
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.