2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-57174
Software Genérico General
9.8
CRITICAL
EPSS
1.5%
2025 2 PoCs

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys hardcoded in the binary. These keys are identical across all devices, allowing attackers to craft encrypted packets that execute arbitrary commands without authentication. This is a failed patch for CVE-2017-7318. This issue may affect other Etherhaul series devices with shared firmware.

CVE-2025-22408
Android General
9.8
CRITICAL
EPSS
2.0%
2025 1 PoC

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-6573
Graphics DDK General
9.8
CRITICAL
EPSS
0.2%
2025 CWE-280 1 PoC

Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).

CVE-2025-45777
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request.

CVE-2025-43951
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.

CVE-2025-32977
Software Genérico General
9.6
CRITICAL
EPSS
0.2%
2025 3 PoCs

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to upload backup files to the system. While signature validation is implemented, weaknesses in the validation process can be exploited to upload malicious backup content that could compromise system integrity.

CVE-2025-10284
bbot General
9.6
CRITICAL
EPSS
0.2%
2025 CWE-22 1 PoC

BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.

CVE-2025-53964
Software Genérico General
9.6
CRITICAL
EPSS
0.1%
2025 1 PoC

GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary and then searches for any term included in that dictionary.

CVE-2025-43728
ThinOS 10 General
9.6
CRITICAL
EPSS
0.2%
2025 CWE-693 1 PoC

Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

CVE-2025-6514
Software Genérico General
9.6
CRITICAL
EPSS
6.2%
2025 CWE-78 2 PoCs

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL

CVE-2025-10283
bbot General
9.6
CRITICAL
EPSS
0.1%
2025 CWE-22 1 PoC

BBOT's gitdumper module could be abused to execute commands through a malicious git repository.

CVE-2025-10894
Software Genérico General
9.6
CRITICAL
EPSS
0.1%
2025 CWE-506 1 PoC

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

CVE-2025-6523
Server General
9.5
CRITICAL
EPSS
0.1%
2025 CWE-1391 1 PoC

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier

CVE-2025-24971
DumbDrop General
9.5
CRITICAL
EPSS
10.3%
2025 CWE-78 1 PoC

DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, `/upload/init` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely when the **Apprise Notification** enabled. This issue has been addressed in commit `4ff8469d` and all users are advised to patch. There are no known workarounds for this vulnerability.

CVE-2025-54948
🔥 KEV Trend Micro Apex One General
9.4
CRITICAL
EPSS
8.8%
2025 CWE-78 1 PoC

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

CVE-2025-30216
CryptoLib General
9.4
CRITICAL
EPSS
7.7%
2025 CWE-122 1 PoC

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a Heap Overflow vulnerability occurs in the `Crypto_TM_ProcessSecurity` function (`crypto_tm.c:1735:8`). When processing the Secondary Header Length of a TM protocol packet, if the Secondary Header Length exceeds the packet's total length, a heap overflow is triggered during the memcpy operation that copies packet data into the dynamicall

CVE-2025-59793
Software Genérico General
9.4
CRITICAL
EPSS
0.8%
2025 1 PoC

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to arbitrary local filesystem locations and may subsequently lead to remote code execution.

CVE-2025-34024
Edimax EW-7438RPn Mini General
9.4
CRITICAL
EPSS
4.3%
2025 CWE-78 1 PoC

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.

CVE-2025-56749
Software Genérico General
9.4
CRITICAL
EPSS
0.1%
2025 1 PoC

Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.

CVE-2025-34056
IP camera, DVR, and NVR Devices General
9.4
CRITICAL
EPSS
2.0%
2025 CWE-78 2 PoCs

An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation. This allows for the execution of arbitrary shell commands with root privileges.