979 vulnerabilidades · Windows · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-10152
Simple Certain Time to Show Content Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.6%
2024 1 PoC

The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12638
Bulk Me Now! Web Windows ⚡ nuclei
7.1
HIGH
EPSS
2.2%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-14015
WordPress eCommerce Plugin Web Windows ⚡ nuclei
7.1
HIGH
EPSS
0.4%
2024 1 PoC

The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-11320
Pandora FMS Windows ⚡ nuclei
6.9
MEDIUM
EPSS
92.6%
2024 CWE-77 2 PoCs

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

CVE-2024-5522
HTML5 Video Player Web Database Windows ⚡ nuclei
6.5
MEDIUM
EPSS
83.8%
2024 6 PoCs

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2024-7714
AI ChatBot with ChatGPT and Content Generator by AYS Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
23.9%
2024 1 PoC

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CVE-2024-9161
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
20.0%
2024 CWE-862 0 PoCs

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators.

CVE-2024-9765
EKC Tournament Manager Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
4.6%
2024 1 PoC

The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

CVE-2019-5591
🔥 KEV Fortinet FortiOS Networking Windows ⚡ nuclei
6.5
MEDIUM
EPSS
48.4%
2019 0 PoCs

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

CVE-2021-41349
Microsoft Exchange Server 2013 Cumulative Update 23 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
91.1%
2021 2 PoCs

Microsoft Exchange Server Spoofing Vulnerability

CVE-2021-31195
Microsoft Exchange Server 2016 Cumulative Update 19 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
79.8%
2021 0 PoCs

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2025-49706
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
75.0%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-3472
Ocean Extra Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
17.3%
2025 CWE-94 0 PoCs

The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.

CVE-2025-53771
Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
39.6%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2020-36728
Adning Advertising Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
83.1%
2020 CWE-22 1 PoC

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to reset and gain full control of a site.

CVE-2023-0948
Japanized For WooCommerce Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
22.9%
2023 1 PoC

The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-23491
Quick Event Manager WordPress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
11.1%
2023 1 PoC

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

CVE-2023-1080
GN Publisher: Google News Compatible RSS Feeds Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
44.7%
2023 CWE-79 0 PoCs

The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-2023
Custom 404 Pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
80.9%
2023 2 PoCs

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2023-6000
Popup Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
69.1%
2023 4 PoCs

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.