2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-34434
AVideo General
9.3
CRITICAL
EPSS
0.3%
2025 CWE-306 1 PoC

AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints responsible for managing gallery images fail to enforce authentication checks and do not validate ownership, allowing unauthenticated attackers to upload or delete images associated with any image-based video.

CVE-2025-32434
pytorch General
9.3
CRITICAL
EPSS
1.2%
2025 CWE-502 1 PoC

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.

CVE-2025-25292
ruby-saml General
9.3
CRITICAL
EPSS
4.7%
2025 CWE-347 1 PoC

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 contain a patch for the issue.

CVE-2025-41426
Liebert RDU101 General
9.3
CRITICAL
EPSS
0.9%
2025 CWE-121 1 PoC

Affected Vertiv products contain a stack based buffer overflow vulnerability. An attacker could exploit this vulnerability to gain code execution on the device.

CVE-2025-11849
mammoth General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-22 4 PoCs

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker ca

CVE-2025-15111
lares General
9.3
CRITICAL
EPSS
0.0%
2025 CWE-259 1 PoC

Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.

CVE-2025-34186
EVE X1/X5 Server General
9.3
CRITICAL
EPSS
0.8%
2025 CWE-287 1 PoC

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.

CVE-2025-32711
Microsoft 365 Copilot General
9.3
CRITICAL
EPSS
10.7%
2025 CWE-74 1 PoC

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2025-7850
Omada gateways General
9.3
CRITICAL
EPSS
1.0%
2025 CWE-78 1 PoC

A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

CVE-2025-27593
SICK DL100-2xxxxxxx General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-494 1 PoC

The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems.

CVE-2025-46412
Liebert RDU101 General
9.3
CRITICAL
EPSS
0.3%
2025 CWE-288 1 PoC

Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.

CVE-2025-15113
lares General
9.3
CRITICAL
EPSS
0.0%
2025 CWE-256 1 PoC

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.

CVE-2025-7426
TTA General
9.3
CRITICAL
EPSS
0.0%
2025 CWE-200 1 PoC

Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP server is part of automated business processes (e.g. EDI or data integration), this could lead to data manipulation, extraction, or abuse.  Debug ports 1602, 1603 and 1636 also expose service architecture information and system activity logs

CVE-2025-34127
Achat Chat Server General
9.3
CRITICAL
EPSS
56.3%
2025 CWE-121 2 PoCs

A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-supplied input leading to remote code execution.

CVE-2025-34299
Monsta FTP General ⚡ nuclei
9.3
CRITICAL
EPSS
69.6%
2025 CWE-434 1 PoC

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

CVE-2025-34516
EVE X1 Server General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-1392 1 PoC

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

CVE-2025-34068
WLAN AP WEA453e General
9.3
CRITICAL
EPSS
3.4%
2025 CWE-306 1 PoC

An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.2.4.T1 via improper input validation in the “Tech Support” diagnostic functionality. The command1 and command2 POST or GET parameters accept arbitrary shell commands that are executed with root privileges on the underlying operating system. An attacker can exploit this by crafting a request that injects shell commands to create output files in writable directories and then access their contents via the download endpoint. This flaw allows complete compromise of the device with

CVE-2025-25038
MiniDVBLinux General
9.3
CRITICAL
EPSS
29.2%
2025 CWE-78 2 PoCs

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.

CVE-2025-53391
zulucrypt General
9.3
CRITICAL
EPSS
0.1%
2025 CWE-863 2 PoCs

The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.