2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-24241
macOS General
9.8
CRITICAL
EPSS
0.6%
2025 1 PoC

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to trick a user into copying sensitive data to the pasteboard.

CVE-2025-68615
net-snmp General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-119 2 PoCs

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.

CVE-2025-24260
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker in a privileged position may be able to perform a denial-of-service.

CVE-2025-70233
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard.

CVE-2025-43946
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2025 1 PoC

TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).

CVE-2025-44893
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 2 PoCs

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.

CVE-2025-44894
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.

CVE-2025-49223
billboard.js General
9.8
CRITICAL
EPSS
0.8%
2025 CWE-1321 1 PoC

billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

CVE-2025-24172
macOS General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All Remote Content" may not apply for all mail previews.

CVE-2025-49533
Adobe Experience Manager (MS) General ⚡ nuclei
9.8
CRITICAL
EPSS
76.4%
2025 CWE-502 0 PoCs

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

CVE-2025-51543
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password endpoint.

CVE-2025-10542
iMonitor EAM General
9.8
CRITICAL
EPSS
0.2%
2025 CWE-1392 3 PoCs

iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This enables reading highly sensitive telemetry (including keylogger output) and issuing arbitrary actions to all connected clients.

CVE-2025-25570
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
20.6%
2025 0 PoCs

Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.

CVE-2025-26063
Software Genérico General
9.8
CRITICAL
EPSS
1.7%
2025 3 PoCs

An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.

CVE-2025-52689
OmniAccess Stellar Products General
9.8
CRITICAL
EPSS
0.8%
2025 CWE-384 2 PoCs

Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the access point.

CVE-2025-10127
Security Gateway General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-640 1 PoC

Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.

CVE-2025-66043
libbiosig General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-121 1 PoC

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 3

CVE-2025-32375
BentoML General
9.8
CRITICAL
EPSS
67.3%
2025 CWE-502 1 PoC

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server. This vulnerability is fixed in 1.4.8.

CVE-2025-44891
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.

CVE-2025-28035
Software Genérico General
9.8
CRITICAL
EPSS
6.4%
2025 2 PoCs

TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.