4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-29745
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.

CVE-2025-7442
WPGYM - Wordpress Gym Management System Web Database Windows
7.5
HIGH
EPSS
0.3%
2025 CWE-89 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters in the MJ_gmgt_delete_class_limit_for_member, MJ_gmgt_get_yearly_income_expense, MJ_gmgt_get_monthly_income_expense, MJ_gmgt_add_class_limit, MJ_gmgt_view_meeting_detail, and MJ_gmgt_create_meeting functions in all versions up to 67.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that

CVE-2025-1361
IP2Location Country Blocker Web Windows ⚡ nuclei
7.5
HIGH
EPSS
8.3%
2025 CWE-285 0 PoCs

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

CVE-2025-29810
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
0.1%
2025 CWE-284 1 PoC

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

CVE-2025-38501
Linux Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.

CVE-2025-5334
Remote Desktop Manager Windows
7.5
HIGH
EPSS
0.4%
2025 CWE-359 1 PoC

Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users. This issue affects the following versions : * Remote Desktop Manager Windows 2025.1.34.0 and earlier * Remote Desktop Manager macOS 2025.1.16.3 and earlier * Remote Desktop Manager Andr

CVE-2025-27456
Endress+Hauser MEAC300-FNADE4 Windows
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-2539
File Away Web Windows ⚡ nuclei
7.5
HIGH
EPSS
20.7%
2025 CWE-327 5 PoCs

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-21181
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
13.6%
2025 CWE-400 2 PoCs

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-26686
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
0.4%
2025 CWE-591 1 PoC

Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

CVE-2025-45994
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1.

CVE-2025-7007
Antivirus Windows
7.5
HIGH
EPSS
0.0%
2025 CWE-476 1 PoC

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash.This issue affects Antivirus: 16.0.0; Anitvirus: 3.0.3.

CVE-2025-6970
Events Manager – Calendar, Bookings, Tickets, and more! Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
37.6%
2025 CWE-89 1 PoC

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-8422
Propovoice: All-in-One Client Management System Web Windows
7.5
HIGH
EPSS
0.1%
2025 CWE-73 1 PoC

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the send_email() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-11855
age-restriction Web Windows
7.5
HIGH
EPSS
0.0%
2025 1 PoC

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.

CVE-2025-10162
Admin and Customer Messages After Order for WooCommerce: OrderConvo Web Windows ⚡ nuclei
7.5
HIGH
EPSS
38.8%
2025 1 PoC

The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack

CVE-2025-30397
🔥 KEV Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
20.7%
2025 CWE-843 4 PoCs

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

CVE-2025-2011
Depicter — Popup & Slider Builder Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
52.4%
2025 CWE-89 1 PoC

The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-54313
🔥 KEV eslint-config-prettier Windows
7.5
HIGH
EPSS
11.6%
2025 CWE-506 3 PoCs

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CVE-2025-27210
node Web Windows
7.5
HIGH
EPSS
4.0%
2025 3 PoCs

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.