11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-32113
SAP GUI for Windows Windows
7.5
HIGH
EPSS
0.2%
2023 CWE-200 1 PoC

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.

CVE-2024-12812
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Windows
7.5
HIGH
EPSS
0.3%
2024 1 PoC

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.

CVE-2026-4338
ActivityPub Web Windows
7.5
HIGH
EPSS
0.1%
2026 1 PoC

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts

CVE-2022-4746
FluentAuth Web Windows
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.

CVE-2023-1405
Formidable Forms Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVE-2025-45994
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1.

CVE-2026-1368
Video Conferencing with Zoom Web Windows ⚡ nuclei
7.5
HIGH
EPSS
32.9%
2026 1 PoC

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.

CVE-2025-21181
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
13.6%
2025 CWE-400 2 PoCs

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-26686
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
0.4%
2025 CWE-591 1 PoC

Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

CVE-2023-0331
Correos Oficial Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.

CVE-2021-24881
Passster Web Windows
7.5
HIGH
EPSS
1.1%
2021 1 PoC

The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

CVE-2021-35583
MySQL Server Database Windows
7.5
HIGH
EPSS
1.5%
2021 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Windows). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2020-15166
libzmq Windows
7.5
HIGH
EPSS
0.4%
2020 CWE-400 1 PoC

In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with CURVE/ZAP, legitimate clients will not be able to exchange any message. Handshakes complete successfully, and messages are delivered to the library, but the server application never receives them. This is patched in version 4.3.3.

CVE-2024-13471
DesignThemes Core Features Web Windows
7.5
HIGH
EPSS
0.9%
2024 CWE-22 1 PoC

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.

CVE-2023-6585
WP JobSearch Web Windows
7.5
HIGH
EPSS
0.4%
2023 1 PoC

The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

CVE-2023-30445
DB2 for Linux, UNIX and Windows Windows
7.5
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.

CVE-2023-2180
KIWIZ Invoices Certification & PDF System Web Windows
7.5
HIGH
EPSS
0.6%
2023 1 PoC

The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)

CVE-2024-9935
PDF Generator for WordPress Elementor Web Windows ⚡ nuclei
7.5
HIGH
EPSS
93.8%
2024 CWE-22 3 PoCs

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-24569 may be a duplicate of this issue.

CVE-2023-6113
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated attackers to download said backups later.