11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2026-6265
Cerberus FTP Server Windows
7.3
HIGH
EPSS
0.0%
2026 CWE-278 1 PoC

Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1

CVE-2024-9772
Uix Shortcodes Web Windows ⚡ nuclei
7.3
HIGH
EPSS
9.0%
2024 CWE-94 0 PoCs

The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2025-8061
Dispatcher 3.0 Driver Windows
7.3
HIGH
EPSS
0.0%
2025 CWE-782 1 PoC

A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default.

CVE-2024-10958
WP Photo Album Plus Web Windows
7.3
HIGH
EPSS
55.7%
2024 CWE-94 1 PoC

The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2023-6007
UserPro - Community and User Profile WordPress Plugin Web Windows
7.3
HIGH
EPSS
0.2%
2023 CWE-862 1 PoC

The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

CVE-2021-31843
McAfee Endpoint Security (ENS) for WIndows Windows
7.3
HIGH
EPSS
0.0%
2021 CWE-59 1 PoC

Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.

CVE-2025-1119
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
7.3
HIGH
EPSS
0.5%
2025 CWE-94 1 PoC

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2021-34423
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Windows
7.3
HIGH
EPSS
0.4%
2021 1 PoC

A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.

CVE-2023-36540
Zoom Desktop Client for Windows Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-426 1 PoC

Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2024-40445
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 2 PoCs

A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.

CVE-2023-5934
Travelpayouts: All Travel Brands in One Place Web Windows
7.3
HIGH
EPSS
0.1%
2023 1 PoC

The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers to make a logged in admin update some settings via a CSRF attack

CVE-2024-24806
libuv Windows
7.3
HIGH
EPSS
0.2%
2024 CWE-918 1 PoC

libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its windows counterpart `src/win/getaddrinfo.c`), truncates hostnames to 256 characters before calling `getaddrinfo`. This behavior can be exploited to create addresses like `0x00007f000001`, which are considered valid by `getaddrinfo` and could allow an attacker to craft payloads that resolve to unintended IP addresses, bypassing developer checks. The vulnerability arises due to how the `hostname_ascii` variable (with a length of 256 bytes) is handled in `

CVE-2017-0213
🔥 KEV Windows COM Windows
7.3
HIGH
EPSS
92.4%
2017 8 PoCs

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.

CVE-2023-34118
Zoom Rooms for Windows Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-250 1 PoC

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-31016
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary code, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2023-41929
Software Genérico Windows
7.3
HIGH
EPSS
0.0%
2023 1 PoC

A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)

CVE-2022-3368
"Avira Security" – for Windows Windows
7.3
HIGH
EPSS
3.1%
2022 2 PoCs

A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556.

CVE-2022-39421
VM VirtualBox Database Windows
7.3
HIGH
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows systems only. CVSS 3.1 Base Score 7.3 (Confidentiality, Integr

CVE-2023-31341
μProf Tool Windows
7.3
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.

CVE-2024-23769
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.