2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-65856
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2025 1 PoC

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.

CVE-2025-67114
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2025 1 PoC

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/root credentials from the device's MAC address, enabling authentication bypass and full device access.

CVE-2025-24249
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to check the existence of an arbitrary path on the file system.

CVE-2025-52689
OmniAccess Stellar Products General
9.8
CRITICAL
EPSS
0.8%
2025 CWE-384 2 PoCs

Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the access point.

CVE-2025-55232
Microsoft HPC Pack 2019 General
9.8
CRITICAL
EPSS
1.2%
2025 CWE-502 1 PoC

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.

CVE-2025-24238
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.3%
2025 3 PoCs

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to gain elevated privileges.

CVE-2025-10127
Security Gateway General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-640 1 PoC

Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.

CVE-2025-56218
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

CVE-2025-26063
Software Genérico General
9.8
CRITICAL
EPSS
1.7%
2025 3 PoCs

An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.

CVE-2025-30426
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.4%
2025 3 PoCs

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to enumerate a user's installed apps.

CVE-2025-1044
Unified SecOps Platform General
9.8
CRITICAL
EPSS
0.4%
2025 CWE-287 1 PoC

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336.

CVE-2025-44883
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.

CVE-2025-55346
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 CWE-94 1 PoC

User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the host, by sending a simple POST request.

CVE-2025-8043
Firefox General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.

CVE-2025-50472
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_model_meta()` function of the `ModelFileSystemCache()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized `.mdl` payload, exploiting the use of `pickle.load()` on data from potentially untrusted sources. This vulnerability allows for remote code execution (RCE) by deceiving victims into loading a seemingly harmless checkpoint during a normal training process, thereby enabling attackers to execute arbitrary code

CVE-2025-22952
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
24.9%
2025 0 PoCs

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.

CVE-2025-24172
macOS General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All Remote Content" may not apply for all mail previews.

CVE-2025-25362
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.

CVE-2025-57437
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuration data including: - Model, version, and unique identifiers - Network settings including IP, MAC, DNS - Current stream platform, stream key, and streaming URL - Audio/video configuration This data can be used to hijack live streams or perform network reconnaissance.

CVE-2025-24178
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.2%
2025 3 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to break out of its sandbox.