14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-63221
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system settings, leading to full compromise of the device.

CVE-2025-54576
oauth2-proxy General
9.1
CRITICAL
EPSS
0.2%
2025 CWE-290 1 PoC

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when using the skip_auth_routes configuration option with regex patterns. Attackers can bypass authentication by crafting URLs with query parameters that satisfy configured regex patterns, allowing unauthorized access to protected resources. The issue stems from skip_auth_routes matching against the full request URI. Deployments using skip_auth_routes

CVE-2025-54887
ruby-jwe General
9.1
CRITICAL
EPSS
0.0%
2025 CWE-354 1 PoC

jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. This puts users at risk because JWEs can be modified to decrypt to an arbitrary value, decrypted by observing parsing differences and the GCM internal GHASH key can be recovered. Users are affected by this vulnerability even if they do not use an AES-GCM encryption algorithm for their JWEs. As the GHASH key may have been leaked,

CVE-2025-5098
PrinterShare Mobile Print General
9.1
CRITICAL
EPSS
0.1%
2025 CWE-200 1 PoC

PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization.

CVE-2025-49029
Custom Login And Signup Widget General ⚡ nuclei
9.1
CRITICAL
EPSS
0.7%
2025 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0.

CVE-2025-6205
🔥 KEV DELMIA Apriso General ⚡ nuclei
9.1
CRITICAL
EPSS
77.7%
2025 CWE-862 0 PoCs

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

CVE-2025-29927
next.js General ⚡ nuclei
9.1
CRITICAL
EPSS
92.1%
2025 CWE-285 98 PoCs

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

CVE-2025-32206
Processing Projects General
9.1
CRITICAL
EPSS
0.2%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Server.This issue affects Processing Projects: from n/a through <= 1.0.2.

CVE-2025-22940
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 2 PoCs

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

CVE-2025-32118
CMP – Coming Soon & Maintenance General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.

CVE-2025-39436
I Draw General
9.1
CRITICAL
EPSS
0.1%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0.

CVE-2025-56231
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

CVE-2025-25948
Software Genérico General
9.1
CRITICAL
EPSS
3.2%
2025 1 PoC

Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

CVE-2025-23968
AiBud WP General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through <= 1.9.

CVE-2025-28915
ThemeEgg ToolKit General
9.1
CRITICAL
EPSS
24.9%
2025 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Server.This issue affects ThemeEgg ToolKit: from n/a through <= 1.2.9.

CVE-2025-46271
UNI-NMS-Lite General
9.1
CRITICAL
EPSS
5.7%
2025 CWE-78 1 PoC

UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

CVE-2025-28230
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 1 PoC

Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.

CVE-2025-47549
BEAF General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Upload a Web Shell to a Web Server.This issue affects BEAF: from n/a through <= 4.6.10.

CVE-2025-28231
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 1 PoC

Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.

CVE-2025-27680
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmware Image with Insufficient Verification of Data Authenticity V-2024-004.