5 vulnerabilidades · Windows · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2026-28414
gradio Windows ⚡ nuclei
7.5
HIGH
EPSS
3.2%
2026 CWE-36 0 PoCs

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read arbitrary files from the file system. Python 3.13+ changed the definition of `os.path.isabs` so that root-relative paths like `/windows/win.ini` on Windows are no longer considered absolute paths, resulting in a vulnerability in Gradio's logic for joining paths safely. This can be exploited by unauthenticated attackers to read arbitrary files from the Gradio

CVE-2026-2025
Mail Mint Web Windows ⚡ nuclei
7.5
HIGH
EPSS
28.0%
2026 1 PoC

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog

CVE-2026-1368
Video Conferencing with Zoom Web Windows ⚡ nuclei
7.5
HIGH
EPSS
32.9%
2026 1 PoC

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.

CVE-2026-0829
Frontend File Manager Plugin Web Windows ⚡ nuclei
5.8
MEDIUM
EPSS
2.6%
2026 1 PoC

The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

CVE-2026-4106
HT Mega Addons for Elementor Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
0.8%
2026 1 PoC

The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days