4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-5998
PPWP – Password Protect Pages Web Windows
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater roles can view content via the REST API.

CVE-2025-55311
Software Genérico Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.

CVE-2025-12685
WPBookit Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.

CVE-2025-8994
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from th

CVE-2025-1013
Firefox Windows
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

CVE-2025-12573
Bookingor Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, allowing low-privileged users to delete Bookingor WordPress plugin through 1.0.12 data.

CVE-2025-49706
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
75.0%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-15488
Responsive Plus Web Windows
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as a shortcode.

CVE-2025-14545
YML for Yandex Market Web Windows
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation process.

CVE-2025-9215
StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-22 2 PoCs

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the file_download() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-1635
Remote Desktop Manager Windows
6.5
MEDIUM
EPSS
0.3%
2025 CWE-200 1 PoC

Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows a user exporting a hub data source to include his authenticated session in the export due to faulty business logic.

CVE-2025-15400
OpenPix for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing persistent disruption of OpenPix payment functionality.

CVE-2025-13380
AI Engine for WordPress: ChatGPT, GPT Content Generator Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-73 2 PoCs

The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1. This is due to insufficient validation of user-supplied file paths in the 'lqdai_update_post' AJAX endpoint and the use of file_get_contents() with user-controlled URLs without protocol restrictions in the insert_image() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-3472
Ocean Extra Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
17.3%
2025 CWE-94 0 PoCs

The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.

CVE-2025-53771
Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
39.6%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-59214
Windows 10 Version 1507 Windows
6.5
MEDIUM
EPSS
0.1%
2025 CWE-200 3 PoCs

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-13683
Server Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

CVE-2025-13922
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied parameters and lack of SQL query parameterization. This makes it possible for authenticated attackers, with Contributor-level access and above who have AI metabox permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information

CVE-2025-11705
Anti-Malware Security and Brute-Force Firewall Web Networking Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to a missing capability check combined with an information exposure in several GOTMLS_* AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.