11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-46619
Software Genérico Windows
7.6
HIGH
EPSS
0.5%
2025 2 PoCs

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.

CVE-2025-27461
Endress+Hauser MEAC300-FNADE4 Windows
7.6
HIGH
EPSS
0.3%
2025 CWE-862 1 PoC

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

CVE-2023-29050
OX App Suite Windows
7.6
HIGH
EPSS
0.1%
2023 CWE-90 1 PoC

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load on the directory server, leading to denial of service. Encoding has been added for user-provided fragments that are used when constructing the LDAP query. No publicly available exploits are known.

CVE-2024-3405
WP Prayer Web Windows
7.6
HIGH
EPSS
0.2%
2024 1 PoC

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2020-6168
Software Genérico Web Windows
7.6
HIGH
EPSS
1.2%
2020 2 PoCs

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).

CVE-2025-27460
Endress+Hauser MEAC300-FNADE4 Windows
7.6
HIGH
EPSS
0.1%
2025 CWE-312 1 PoC

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows login. The attacker can read from and write to all files on the hard drives.

CVE-2024-6205
PayPlus Payment Gateway Web Database Windows ⚡ nuclei
7.6
HIGH
EPSS
90.4%
2024 2 PoCs

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.

CVE-2020-6275
SAP Netweaver AS ABAP Windows
7.6
HIGH
EPSS
0.5%
2020 1 PoC

SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into authenticating with the malicious server. Furthermore, if NTLM is setup the attacker can compromise confidentiality, integrity and availability of the SAP database.

CVE-2019-0709
Windows 10 Version 1703 Windows
7.6
HIGH
EPSS
37.3%
2019 3 PoCs

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code. An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system. The security update addresses the vulnerability by correcting how Hyper-V validates guest operating system user input.

CVE-2023-5644
WP Mail Log Web Windows
7.6
HIGH
EPSS
0.1%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

CVE-2024-5429
Logo Slider Web Windows
7.6
HIGH
EPSS
0.4%
2024 1 PoC

The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2025-12055
MIP 2 Windows ⚡ nuclei
7.5
HIGH
EPSS
22.3%
2025 CWE-22 2 PoCs

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.

CVE-2024-4469
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.7%
2024 1 PoC

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

CVE-2025-10162
Admin and Customer Messages After Order for WooCommerce: OrderConvo Web Windows ⚡ nuclei
7.5
HIGH
EPSS
38.8%
2025 1 PoC

The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack

CVE-2025-21181
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
13.6%
2025 CWE-400 2 PoCs

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2024-13471
DesignThemes Core Features Web Windows
7.5
HIGH
EPSS
0.9%
2024 CWE-22 1 PoC

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.

CVE-2024-6973
SDP Client Windows
7.5
HIGH
EPSS
1.5%
2024 CWE-20 1 PoC

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

CVE-2024-13488
LTL Freight Quotes – Estes Edition Web Database Windows
7.5
HIGH
EPSS
15.1%
2024 CWE-89 1 PoC

The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-49113
Windows 10 Version 1809 Windows
7.5
HIGH
EPSS
88.9%
2024 CWE-125 3 PoCs

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2024-13483
LTL Freight Quotes – SAIA Edition Web Database Windows
7.5
HIGH
EPSS
3.9%
2024 CWE-89 1 PoC

The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 2.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.