606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-3516
Simple Lightbox Web Windows
5.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The Simple Lightbox WordPress plugin before 2.9.4 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-13031
WPeMatico RSS Feed Fetcher Web Windows
5.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2025-3201
Contact Form builder with drag & drop for WordPress Web Windows
5.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.

CVE-2025-31947
Mattermost Windows
5.8
MEDIUM
EPSS
0.4%
2025 CWE-645 1 PoC

Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.

CVE-2025-5921
SureForms Web Windows
5.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.

CVE-2025-8280
Contact Form 7 reCAPTCHA Web Windows
5.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.

CVE-2025-9116
WPS Visitor Counter Web Windows
5.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.

CVE-2025-11427
WP Migrate Lite – Migration Made Easy Web Windows
5.8
MEDIUM
EPSS
0.1%
2025 CWE-918 1 PoC

The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.7.6 via the wpmdb_flush AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to obtain information about internal services.

CVE-2025-9115
Etsy Shop Web Windows
5.6
MEDIUM
EPSS
0.0%
2025 1 PoC

The Etsy Shop WordPress plugin before 3.0.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.

CVE-2025-10406
BlindMatrix e-Commerce Web Windows
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI attacks.

CVE-2025-53009
MaterialX Windows
5.5
MEDIUM
EPSS
0.6%
2025 CWE-121 1 PoC

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack exhaustion. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file. This is fixed in version 1.39.3.

CVE-2025-10874
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Web Windows
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

CVE-2025-21844
Linux Windows
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of cifs_buf_get() and cifs_small_buf_get() in receive_encrypted_standard() to prevent null pointer dereference.

CVE-2025-15491
Post Slides Web Windows
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as with contributor or higher roles to perform LFI attacks

CVE-2025-2247
WP-PManager Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-11154
IDonate Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

CVE-2025-3414
Structured Content (JSON-LD) #wpsc Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-12905
Chrome Windows
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-3941
Niagara Framework Windows
5.4
MEDIUM
EPSS
0.4%
2025 CWE-69 1 PoC

Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-2499
Remote Desktop Manager Windows
5.4
MEDIUM
EPSS
0.1%
2025 CWE-284 1 PoC

Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictions—specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.