11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-4302
Stop User Enumeration Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
1.1%
2025 1 PoC

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

CVE-2025-13820
Comments Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

CVE-2025-32098
Software Genérico Windows
5.3
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.

CVE-2023-5561
WordPress Web Database Windows ⚡ nuclei
5.3
MEDIUM
EPSS
53.0%
2023 5 PoCs

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVE-2025-10645
WP Reset Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-532 1 PoC

The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license key and site data.

CVE-2025-11072
MelAbu WP Download Counter Button Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files.

CVE-2025-11996
Find Unused Images Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's attachments.

CVE-2025-5815
Traffic Monitor Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging.

CVE-2023-6155
Quiz Maker Web Windows
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

CVE-2025-12841
Bookit Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.

CVE-2025-3940
Niagara Framework Windows
5.3
MEDIUM
EPSS
0.3%
2025 CWE-1173 1 PoC

Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-11191
RealPress Web Windows
5.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

CVE-2020-26195
PowerScale OneFS Windows
5.3
MEDIUM
EPSS
1.2%
2020 CWE-280 1 PoC

Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user. A remote unauthenticated attacker may take advantage of this issue to slow down the system.

CVE-2025-10873
ElementInvader Addons for Elementor Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses due to missing authorization on the elementinvader_addons_for_elementor_forms_send_form action.

CVE-2025-8999
Sydney Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' function in all versions up to, and including, 2.56. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or deactivate various theme modules.

CVE-2025-6082
Birth Chart Compatibility Web Windows
5.3
MEDIUM
EPSS
3.6%
2025 CWE-200 1 PoC

The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to insufficient protection against directly accessing the plugin's index.php file, which causes an error exposing the full path. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

CVE-2025-4893
CoinExchange_CryptoExchange_Java Networking Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d3efbeeb2473d7235bd01436fa. This affects the function uploadLocalImage of the file /CoinExchange_CryptoExchange_Java-master/00_framework/core/src/main/java/com/bizzan/bitrade/util/UploadFileUtil.java of the component File Upload Endpoint. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information abo

CVE-2025-0466
Sensei LMS Web Windows
5.3
MEDIUM
EPSS
0.5%
2025 1 PoC

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

CVE-2023-2751
Upload Resume Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site.

CVE-2023-7232
Backup and Restore WordPress Web Windows
5.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data