4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-2055
MapPress Maps for WordPress Web Windows
6.8
MEDIUM
EPSS
0.5%
2025 1 PoC

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2025-9978
Jeg Kit for Elementor Web Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting vulnerability.

CVE-2025-3649
LightPress Lightbox Web Windows
6.8
MEDIUM
EPSS
0.3%
2025 1 PoC

The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.

CVE-2025-26637
Windows 10 Version 1507 Windows
6.8
MEDIUM
EPSS
1.4%
2025 CWE-693 1 PoC

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2025-14973
Recipe Card Blocks Lite Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks.

CVE-2025-13407
Gravity Forms Web Windows
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

CVE-2025-3742
Responsive Lightbox & Gallery Web Windows
6.8
MEDIUM
EPSS
0.3%
2025 1 PoC

The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-12502
attention-bar Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users such as administrator to perform SQL injection attacks

CVE-2025-14803
NEX-Forms Web Windows
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

CVE-2025-15433
Shared Files Web Windows
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector

CVE-2025-3938
Niagara Framework Windows
6.8
MEDIUM
EPSS
0.2%
2025 CWE-325 1 PoC

Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-2600
Remote Desktop Manager Windows
6.8
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.

CVE-2025-9698
The Plus Addons for Elementor Web Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.

CVE-2025-15441
Form Maker by 10Web Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.

CVE-2025-10010
CryptoPro Secure Disk for BitLocker Windows
6.8
MEDIUM
EPSS
0.0%
2025 CWE-353 2 PoCs

The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before using BitLocker to decrypt the Windows partition. The system is located on a separate unencrypted partition which can be reached by anyone with access to the hard disk. Multiple checks are performed to validate the integrity of the Linux operating system and the CryptoPro Secure Disk application files. When files are changed an error is shown on system start. One of the checks is the Linux kernel's Integrity Measurement Architecture (IMA). It was identified that configuration

CVE-2020-7277
McAfee Endpoint Security (ENS) Windows
6.8
MEDIUM
EPSS
0.1%
2020 CWE-693 1 PoC

Protection mechanism failure in all processes in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows local users to stop certain McAfee ENS processes, reducing the protection offered.

CVE-2020-1034
Windows 10 Version 1803 Windows
6.8
MEDIUM
EPSS
17.0%
2020 3 PoCs

<p>An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.</p> <p>The security update addresses the vulnerability by ensuring the Windows Kernel properly handles objects in memory.</p>

CVE-2020-2601
Java Database Windows
6.8
MEDIUM
EPSS
0.6%
2020 1 PoC

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded

CVE-2018-6674
VirusScan Enterprise (VSE) Windows
6.8
MEDIUM
EPSS
0.0%
2018 CWE-264 1 PoC

Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current user's privileges).

CVE-2022-28185
NVIDIA GPU Display Driver Windows
6.8
MEDIUM
EPSS
0.1%
2022 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.