606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-10635
Find Me On Web Database Windows
7.7
HIGH
EPSS
0.0%
2025 1 PoC

The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks

CVE-2025-14804
Frontend File Manager Plugin Web Windows
7.7
HIGH
EPSS
0.0%
2025 1 PoC

The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server

CVE-2025-3937
Niagara Framework Windows
7.7
HIGH
EPSS
0.1%
2025 CWE-916 1 PoC

Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-13000
db-access Web Database Windows
7.7
HIGH
EPSS
0.0%
2025 1 PoC

The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks

CVE-2025-3033
Firefox Windows
7.7
HIGH
EPSS
0.1%
2025 1 PoC

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

CVE-2025-27461
Endress+Hauser MEAC300-FNADE4 Windows
7.6
HIGH
EPSS
0.3%
2025 CWE-862 1 PoC

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

CVE-2025-46619
Software Genérico Windows
7.6
HIGH
EPSS
0.5%
2025 2 PoCs

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.

CVE-2025-27460
Endress+Hauser MEAC300-FNADE4 Windows
7.6
HIGH
EPSS
0.1%
2025 CWE-312 1 PoC

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows login. The attacker can read from and write to all files on the hard drives.

CVE-2025-3419
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) Web Windows
7.5
HIGH
EPSS
0.2%
2025 CWE-73 1 PoC

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-47445 is a duplicate of this vulnerability.

CVE-2025-10162
Admin and Customer Messages After Order for WooCommerce: OrderConvo Web Windows ⚡ nuclei
7.5
HIGH
EPSS
38.8%
2025 1 PoC

The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack

CVE-2025-27456
Endress+Hauser MEAC300-FNADE4 Windows
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-6970
Events Manager – Calendar, Bookings, Tickets, and more! Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
37.6%
2025 CWE-89 1 PoC

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-12055
MIP 2 Windows ⚡ nuclei
7.5
HIGH
EPSS
22.3%
2025 CWE-22 2 PoCs

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.

CVE-2025-1323
WP-Recall – Registration, Profile, Commerce & More Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
27.3%
2025 CWE-89 1 PoC

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-5287
Likes and Dislikes Plugin Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
10.0%
2025 CWE-89 4 PoCs

The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-2539
File Away Web Windows ⚡ nuclei
7.5
HIGH
EPSS
20.7%
2025 CWE-327 5 PoCs

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-2011
Depicter — Popup & Slider Builder Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
52.4%
2025 CWE-89 1 PoC

The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-12726
Chrome Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

CVE-2025-13029
Knowband Mobile App Builder Web Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users.

CVE-2025-38501
Linux Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.