11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13631
Om Stripe Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12400
tourmaster Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2024-3111
Interactive Content Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and above to update malicious SVG files, leading to Stored Cross-Site Scripting issues

CVE-2024-13352
Legull Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.8%
2024 1 PoC

The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2019-3822
curl Web Windows
7.1
HIGH
EPSS
17.9%
2019 CWE-121 3 PoCs

libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header pro

CVE-2024-13574
XV Random Quotes Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-5034
wp-file-download Web Windows
7.1
HIGH
EPSS
0.2%
2025 1 PoC

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2024-13891
Schedule Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-36949
Microsoft Azure Active Directory Connect 1.X.Y.Z Cloud Windows
7.1
HIGH
EPSS
0.8%
2021 1 PoC

Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability

CVE-2025-1401
WP Click Info Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-9191
Okta Verify for Windows Windows
7.1
HIGH
EPSS
0.2%
2024 CWE-276 1 PoC

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnerability was discovered via routine penetration testing. Note: A precondition of this vulnerability is that the user must be using the Okta Device Access passwordless feature. Okta Device Access users not using passwordless are not affected, and customers only using Okta Verify on platforms other than Windows, or only using FastPass are not aff

CVE-2021-42110
Software Genérico Windows
7.1
HIGH
EPSS
0.1%
2021 2 PoCs

An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.

CVE-2022-31647
Software Genérico DevOps Web Windows
7.1
HIGH
EPSS
0.0%
2022 1 PoC

Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.

CVE-2025-4613
Web Designer App Windows
7.1
HIGH
EPSS
0.2%
2025 CWE-20 1 PoC

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template

CVE-2024-10483
Simple:Press Forum Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2024-10152
Simple Certain Time to Show Content Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.6%
2024 1 PoC

The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-28344
Software Genérico Web Windows
7.1
HIGH
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. Attackers are able to view screenshots of student desktops without their consent. These screenshots may potentially contain sensitive/personal data. Attackers can also rapidly submit falsified images, hiding the actual contents of student desktops from the Teacher Console.

CVE-2024-5287
wp-affiliate-platform Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack

CVE-2023-21752
Windows 10 Version 22H2 Windows
7.1
HIGH
EPSS
33.0%
2023 CWE-284 2 PoCs

Windows Backup Service Elevation of Privilege Vulnerability

CVE-2024-13877
Passbeemedia Web Push Notification Web Windows
7.1
HIGH
EPSS
0.1%
2024 1 PoC

The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.