14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-27593
SICK DL100-2xxxxxxx General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-494 1 PoC

The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems.

CVE-2025-59091
Kaba exos 9300 General
9.3
CRITICAL
EPSS
0.1%
2025 CWE-798 2 PoCs

Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used to graphically visualize open doors and alerts. However, controlling the Access Managers via this interface is also possible. To send and receive status information, authentication is necessary. The Kaba exos 9300 application contains hard-coded credentials for four different users, which are allowed to login to the dat

CVE-2025-34103
WiPG-1000 General
9.3
CRITICAL
EPSS
72.6%
2025 CWE-78 3 PoCs

An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling in the undocumented /cgi-bin/rdfs.cgi endpoint. The Client parameter is not sanitized before being passed to a system call, allowing an unauthenticated remote attacker to execute arbitrary commands as the web server user.

CVE-2025-32711
Microsoft 365 Copilot General
9.3
CRITICAL
EPSS
10.7%
2025 CWE-74 1 PoC

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2025-15113
lares General
9.3
CRITICAL
EPSS
0.0%
2025 CWE-256 1 PoC

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.

CVE-2025-32058
Infotainment system ECU General
9.3
CRITICAL
EPSS
0.0%
2025 CWE-121 2 PoCs

The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the infotainment main SoC to perform code execution on the RH850 module and subsequently send arbitrary CAN messages over the connected CAN bus. First identified on Nissan Leaf ZE1 manufactured in 2020.

CVE-2025-25291
ruby-saml General
9.3
CRITICAL
EPSS
20.8%
2025 CWE-347 1 PoC

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 fix the issue.

CVE-2025-34072
Slack MCP Server General
9.3
CRITICAL
EPSS
0.4%
2025 CWE-200 1 PoC

A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI agent using the Slack MCP Server processes untrusted data, it can be manipulated to generate messages containing attacker-crafted hyperlinks embedding sensitive data. Slack’s link preview bots (e.g., Slack-LinkExpanding, Slackbot, Slack-ImgProxy) will then issue outbound requests to the attacker-controlled URL, resulting in zero-click exfiltration of private data.

CVE-2025-34515
EVE X1 Server General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-250 1 PoC

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

CVE-2025-34164
NetSupport Manager General
9.3
CRITICAL
EPSS
0.8%
2025 CWE-122 1 PoC

A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.

CVE-2025-32434
pytorch General
9.3
CRITICAL
EPSS
1.2%
2025 CWE-502 1 PoC

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.

CVE-2025-34434
AVideo General
9.3
CRITICAL
EPSS
0.3%
2025 CWE-306 1 PoC

AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints responsible for managing gallery images fail to enforce authentication checks and do not validate ownership, allowing unauthenticated attackers to upload or delete images associated with any image-based video.

CVE-2025-34183
EVE X1 Server General
9.3
CRITICAL
EPSS
0.1%
2025 CWE-532 1 PoC

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.

CVE-2025-8730
F9K1009 General
9.3
CRITICAL
EPSS
30.2%
2025 CWE-798 1 PoC

A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-34132
DVR Firmware General
9.3
CRITICAL
EPSS
2.3%
2025 CWE-78 2 PoCs

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface.

CVE-2025-34186
EVE X1/X5 Server General
9.3
CRITICAL
EPSS
0.8%
2025 CWE-287 1 PoC

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.

CVE-2025-25292
ruby-saml General
9.3
CRITICAL
EPSS
4.7%
2025 CWE-347 1 PoC

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 contain a patch for the issue.

CVE-2025-11849
mammoth General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-22 4 PoCs

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker ca

CVE-2025-41426
Liebert RDU101 General
9.3
CRITICAL
EPSS
0.9%
2025 CWE-121 1 PoC

Affected Vertiv products contain a stack based buffer overflow vulnerability. An attacker could exploit this vulnerability to gain code execution on the device.