2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-2775
🔥 KEV SysAid On-Prem General ⚡ nuclei
9.3
CRITICAL
EPSS
69.3%
2025 CWE-611 1 PoC

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

CVE-2025-0851
DeepJavaLibrary General
9.3
CRITICAL
EPSS
43.7%
2025 CWE-36 1 PoC

A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.

CVE-2025-34082
OS General
9.3
CRITICAL
EPSS
64.0%
2025 CWE-78 1 PoC

A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Shadow services. The flaw arises due to improper input sanitization in the handling of specially crafted PROXYCMD commands on TCP ports 30022 and 5900. An unauthenticated attacker with network access to a vulnerable device can inject arbitrary commands, leading to remote code execution with elevated privileges. NOTE: IGEL OS v10.x has reached end-of-life (EOL) status.

CVE-2025-2611
ICTBroadcast General ⚡ nuclei
9.3
CRITICAL
EPSS
71.8%
2025 CWE-78 0 PoCs

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.

CVE-2025-2620
DAP-1620 General
9.3
CRITICAL
EPSS
26.4%
2025 CWE-121 1 PoC

A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2025-52472
xwiki-platform General ⚡ nuclei
9.3
CRITICAL
EPSS
0.2%
2025 CWE-89 0 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0, the REST search URL is vulnerable to HQL injection via the `orderField` parameter. The specified value is added twice in the query, though, once in the field list for the select and once in the order clause, so it's not that easy to exploit. The part of the query between the two fields can be enclosed in single quotes to effectively remove them, but the query still needs to remain valid with the query two

CVE-2025-34034
Blue Angel Software Suite General
9.3
CRITICAL
EPSS
0.4%
2025 CWE-798 1 PoC

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-26 UTC.

CVE-2025-54574
squid General
9.3
CRITICAL
EPSS
3.9%
2025 CWE-122 1 PoC

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.

CVE-2025-15114
lares General
9.3
CRITICAL
EPSS
0.0%
2025 CWE-403 1 PoC

Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.

CVE-2025-53391
zulucrypt General
9.3
CRITICAL
EPSS
0.1%
2025 CWE-863 2 PoCs

The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.

CVE-2025-25038
MiniDVBLinux General
9.3
CRITICAL
EPSS
29.2%
2025 CWE-78 2 PoCs

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.

CVE-2025-46412
Liebert RDU101 General
9.3
CRITICAL
EPSS
0.3%
2025 CWE-288 1 PoC

Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.

CVE-2025-34068
WLAN AP WEA453e General
9.3
CRITICAL
EPSS
3.4%
2025 CWE-306 1 PoC

An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.2.4.T1 via improper input validation in the “Tech Support” diagnostic functionality. The command1 and command2 POST or GET parameters accept arbitrary shell commands that are executed with root privileges on the underlying operating system. An attacker can exploit this by crafting a request that injects shell commands to create output files in writable directories and then access their contents via the download endpoint. This flaw allows complete compromise of the device with

CVE-2025-2776
🔥 KEV SysAid On-Prem General ⚡ nuclei
9.3
CRITICAL
EPSS
62.6%
2025 CWE-611 2 PoCs

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

CVE-2025-34516
EVE X1 Server General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-1392 1 PoC

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

CVE-2025-34299
Monsta FTP General ⚡ nuclei
9.3
CRITICAL
EPSS
69.6%
2025 CWE-434 1 PoC

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

CVE-2020-13539
Win-911 General
9.3
CRITICAL
EPSS
0.1%
2020 CWE-276 2 PoCs

An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via “WIN-911 Mobile Runtime” service. Depending on the vector chosen, an attacker can overwrite various executables which could lead to escalation of the privileges when executed.

CVE-2020-36894
i-Media Server Digital Signage General
9.3
CRITICAL
EPSS
0.6%
2020 CWE-306 2 PoCs

Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attackers can send crafted serialized objects to the /messagebroker/amf endpoint to create administrative users without authentication, bypassing security controls.

CVE-2020-37052
AirControl General
9.3
CRITICAL
EPSS
0.3%
2020 CWE-94 1 PoC

AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.

CVE-2020-13532
Dream Report General
9.3
CRITICAL
EPSS
0.1%
2020 CWE-276 1 PoC

A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges to NT SYSTEM. An attacker can provide a malicious file to trigger this vulnerability.