11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-22947
Software Genérico Windows
7.3
HIGH
EPSS
0.0%
2023 2 PoCs

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

CVE-2023-7231
illi Link Party! Web Windows
7.3
HIGH
EPSS
0.3%
2023 2 PoCs

The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to delete links.

CVE-2023-28346
Software Genérico Web Windows
7.3
HIGH
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this access. Remote attackers can interact with private pages on the web server, enabling them to perform privileged actions such as logging into the console and changing console settings if they have valid credentials.

CVE-2023-36537
Zoom Rooms for Windows Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-354 1 PoC

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-31016
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary code, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2023-5934
Travelpayouts: All Travel Brands in One Place Web Windows
7.3
HIGH
EPSS
0.1%
2023 1 PoC

The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers to make a logged in admin update some settings via a CSRF attack

CVE-2023-36540
Zoom Desktop Client for Windows Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-426 1 PoC

Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-6007
UserPro - Community and User Profile WordPress Plugin Web Windows
7.3
HIGH
EPSS
0.2%
2023 CWE-862 1 PoC

The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

CVE-2024-0683
Bulgarisation for WooCommerce Web Windows
7.3
HIGH
EPSS
26.4%
2024 CWE-862 1 PoC

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and delete labels.

CVE-2024-6750
Social Auto Poster Web Windows
7.3
HIGH
EPSS
0.3%
2024 CWE-862 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.

CVE-2024-20696
Windows 10 Version 1809 Windows
7.3
HIGH
EPSS
7.2%
2024 CWE-122 1 PoC

Windows libarchive Remote Code Execution Vulnerability

CVE-2024-7980
Chrome Windows
7.3
HIGH
EPSS
0.0%
2024 1 PoC

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)

CVE-2024-31954
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (An attacker must already have user privileges)

CVE-2024-5102
Antivirus Windows
7.3
HIGH
EPSS
0.1%
2024 CWE-1284 1 PoC

A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\SYSTEM. A low-privileged user can make a pseudo-symlink and a junction folder and point to a file on the system. This can provide a low-privileged user an Elevation of Privilege to win a race-condition which will re-create the s

CVE-2024-13346
Avada | Website Builder For WordPress & WooCommerce Web Windows
7.3
HIGH
EPSS
41.3%
2024 CWE-94 1 PoC

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2024-9061
WP Popup Builder – Popup Forms and Marketing Lead Generation Web Windows ⚡ nuclei
7.3
HIGH
EPSS
89.0%
2024 CWE-94 1 PoC

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. How

CVE-2024-23769
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

CVE-2024-24806
libuv Windows
7.3
HIGH
EPSS
0.2%
2024 CWE-918 1 PoC

libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its windows counterpart `src/win/getaddrinfo.c`), truncates hostnames to 256 characters before calling `getaddrinfo`. This behavior can be exploited to create addresses like `0x00007f000001`, which are considered valid by `getaddrinfo` and could allow an attacker to craft payloads that resolve to unintended IP addresses, bypassing developer checks. The vulnerability arises due to how the `hostname_ascii` variable (with a length of 256 bytes) is handled in `

CVE-2024-9772
Uix Shortcodes Web Windows ⚡ nuclei
7.3
HIGH
EPSS
9.0%
2024 CWE-94 0 PoCs

The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2024-35061
Software Genérico Windows
7.3
HIGH
EPSS
1.4%
2024 1 PoC

NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.