40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-30220
geoserver General ⚡ nuclei
9.9
CRITICAL
EPSS
13.9%
2025 CWE-611 0 PoCs

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used

CVE-2025-46157
Software Genérico General
9.9
CRITICAL
EPSS
0.9%
2025 1 PoC

An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form

CVE-2025-26892
Celestial Aura General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

CVE-2025-32682
MapSVG General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through <= 8.6.4.

CVE-2025-20051
Mattermost General
9.9
CRITICAL
EPSS
0.3%
2025 CWE-22 1 PoC

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially crafted block in Boards.

CVE-2025-30911
RTMKit General
9.9
CRITICAL
EPSS
1.7%
2025 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.

CVE-2025-32579
Sync Posts General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects Sync Posts: from n/a through <= 1.0.

CVE-2025-46093
LiquidFiles General
9.9
CRITICAL
EPSS
0.2%
2025 CWE-732 1 PoC

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

CVE-2025-27554
ToDesktop General
9.9
CRITICAL
EPSS
0.6%
2025 CWE-94 1 PoC

ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a postinstall script in package.json. No exploitation occurred.

CVE-2020-6081
3S General
9.9
CRITICAL
EPSS
0.9%
2020 1 PoC

An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2020-15149
NodeBB General
9.9
CRITICAL
EPSS
0.4%
2020 CWE-269 2 PoCs

NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation event due via an account takeover. As a workaround you may cherry-pick the following commit from the project's repository to your running instance of NodeBB: 16cee1b03ba3eee177834a1fdac4aa8a12b39d2a. This is fixed in version 1.14.3.

CVE-2020-29396
Odoo Community General
9.9
CRITICAL
EPSS
1.8%
2020 CWE-267 1 PoC

A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.

CVE-2020-9045
Software House C•CURE 9000 v2.70 General
9.9
CRITICAL
EPSS
0.1%
2020 CWE-312 2 PoCs

During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation.

CVE-2022-2550
hestiacp/hestiacp General
9.9
CRITICAL
EPSS
8.8%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.

CVE-2022-37425
Software Genérico General
9.9
CRITICAL
EPSS
2.1%
2022 1 PoC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.

CVE-2022-1770
polonel/trudesk General
9.9
CRITICAL
EPSS
0.3%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-46642
Software Genérico General
9.9
CRITICAL
EPSS
6.9%
2022 1 PoC

D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.

CVE-2022-0415
gogs/gogs General ⚡ nuclei
9.9
CRITICAL
EPSS
89.6%
2022 CWE-20 1 PoC

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

CVE-2022-1699
causefx/organizr General
9.9
CRITICAL
EPSS
0.3%
2022 CWE-190 1 PoC

Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVE-2022-41203
SAP BusinessObjects Business Intelligence Platform (Central Management Console and BI Launchpad) General
9.9
CRITICAL
EPSS
1.0%
2022 CWE-502 1 PoC

In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with another malicious serialized object, which leads to deserialization of untrusted data vulnerability. This could highly compromise the Confidentiality, Integrity, and Availability of the system.