2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-45931
Software Genérico General
9.8
CRITICAL
EPSS
4.7%
2025 1 PoC

An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file

CVE-2025-30424
macOS General
9.8
CRITICAL
EPSS
0.7%
2025 1 PoC

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Deleting a conversation in Messages may expose user contact information in system logging.

CVE-2025-52688
OmniAccess Stellar Products General
9.8
CRITICAL
EPSS
0.2%
2025 CWE-77 2 PoCs

Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.

CVE-2025-63217
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.

CVE-2025-56819
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
11.8%
2025 1 PoC

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

CVE-2025-70221
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.

CVE-2025-46108
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.

CVE-2025-67135
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

CVE-2025-65482
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 3 PoCs

An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.

CVE-2025-6573
Graphics DDK General
9.8
CRITICAL
EPSS
0.2%
2025 CWE-280 1 PoC

Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).

CVE-2025-22408
Android General
9.8
CRITICAL
EPSS
2.0%
2025 1 PoC

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-25940
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2025 1 PoC

VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.

CVE-2025-28024
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi

CVE-2025-52046
Software Genérico General
9.8
CRITICAL
EPSS
54.4%
2025 1 PoC

Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.

CVE-2025-63223
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2025 1 PoC

The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system settings, leading to full compromise of the device.

CVE-2025-44887
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

CVE-2025-28399
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

CVE-2025-1066
OpenPLC General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.

CVE-2025-46120
Software Genérico General
9.8
CRITICAL
EPSS
2.5%
2025 1 PoC

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.

CVE-2025-27638
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Hardcoded Password V-2024-013.