606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-5287
Likes and Dislikes Plugin Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
10.0%
2025 CWE-89 4 PoCs

The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-12726
Chrome Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

CVE-2025-30397
🔥 KEV Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
20.7%
2025 CWE-843 4 PoCs

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

CVE-2025-13029
Knowband Mobile App Builder Web Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users.

CVE-2025-27456
Endress+Hauser MEAC300-FNADE4 Windows
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-21181
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
13.6%
2025 CWE-400 2 PoCs

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-29745
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.

CVE-2025-7442
WPGYM - Wordpress Gym Management System Web Database Windows
7.5
HIGH
EPSS
0.3%
2025 CWE-89 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters in the MJ_gmgt_delete_class_limit_for_member, MJ_gmgt_get_yearly_income_expense, MJ_gmgt_get_monthly_income_expense, MJ_gmgt_add_class_limit, MJ_gmgt_view_meeting_detail, and MJ_gmgt_create_meeting functions in all versions up to 67.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that

CVE-2025-2011
Depicter — Popup & Slider Builder Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
52.4%
2025 CWE-89 1 PoC

The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-5334
Remote Desktop Manager Windows
7.5
HIGH
EPSS
0.4%
2025 CWE-359 1 PoC

Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users. This issue affects the following versions : * Remote Desktop Manager Windows 2025.1.34.0 and earlier * Remote Desktop Manager macOS 2025.1.16.3 and earlier * Remote Desktop Manager Andr

CVE-2025-1361
IP2Location Country Blocker Web Windows ⚡ nuclei
7.5
HIGH
EPSS
8.3%
2025 CWE-285 0 PoCs

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

CVE-2025-2010
JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
22.8%
2025 CWE-89 0 PoCs

The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injection via the 'jobwp_upload_resume' parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-30194
DNSdist Web Windows
7.5
HIGH
EPSS
0.3%
2025 CWE-416 2 PoCs

When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A workaround is to temporarily switch to the h2o provider until DNSdist has been upgraded to a fixed version. We would like to thank Charles Howes for bringing this issue to our attention.

CVE-2025-6970
Events Manager – Calendar, Bookings, Tickets, and more! Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
37.6%
2025 CWE-89 1 PoC

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-29810
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
0.1%
2025 CWE-284 1 PoC

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

CVE-2025-2539
File Away Web Windows ⚡ nuclei
7.5
HIGH
EPSS
20.7%
2025 CWE-327 5 PoCs

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-4396
Relevanssi Premium Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
22.0%
2025 CWE-89 0 PoCs

The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.

CVE-2025-65176
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is installed and receiving a "STATUS_LOGON_FAILURE" error, the agent will retrieve every user token on the machine and repeatedly attempt to access the network share while impersonating them. The exploitation of this vulnerability can allow an unprivileged attacker with access to the affected system to perform NTLM relay attacks.

CVE-2025-4840
inprosysmedia-likes-dislikes-post Web Database Windows
7.5
HIGH
EPSS
0.2%
2025 2 PoCs

The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2025-58726
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
0.1%
2025 CWE-284 2 PoCs

Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.