555 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-14799
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.2%
2019 2 PoCs

The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

CVE-2019-20211
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 7 PoCs

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.

CVE-2019-1230
Windows Windows
N/A
UNKNOWN
EPSS
2.7%
2019 1 PoC

An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'.

CVE-2019-11591
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 3 PoCs

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.

CVE-2019-14679
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.

CVE-2019-15659
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.

CVE-2019-12574
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability during the software update process. The updater loads several libraries from a folder that authenticated users have write access to. A low privileged user can leverage this vulnerability to execute arbitrary code as SYSTEM.

CVE-2019-1345
Windows Server Windows
N/A
UNKNOWN
EPSS
5.3%
2019 1 PoC

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1334.

CVE-2019-17235
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.

CVE-2019-20182
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.

CVE-2019-14348
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
29.0%
2019 2 PoCs

The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.

CVE-2019-15826
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.

CVE-2019-9912
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2019 2 PoCs

The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.

CVE-2019-0623
Windows Windows
N/A
UNKNOWN
EPSS
34.2%
2019 2 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVE-2019-15895
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.

CVE-2019-15109
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.

CVE-2019-15598
treekill Windows
N/A
UNKNOWN
EPSS
3.8%
2019 CWE-94 1 PoC

A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

CVE-2019-15646
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

The rsvpmaker plugin before 6.2 for WordPress has SQL injection.

CVE-2019-14743
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access.

CVE-2019-5684
GPU Display Driver Windows
N/A
UNKNOWN
EPSS
2.5%
2019 1 PoC

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.