2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-15586
OGP-Website General
10.0
CRITICAL
EPSS
0.1%
2025 CWE-287 1 PoC

OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in authentication bypass without knowledge of the victim account's password.

CVE-2025-63216
Software Genérico General
10.0
CRITICAL
EPSS
0.2%
2025 1 PoC

The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.

CVE-2025-9962
P series (P07, P10, P12, P15) General
10.0
CRITICAL
EPSS
0.1%
2025 CWE-120 2 PoCs

A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authentication.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

CVE-2025-42944
SAP Netweaver (RMI-P4) General
10.0
CRITICAL
EPSS
0.2%
2025 CWE-502 1 PoC

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability.

CVE-2025-54322
SXZOS General
10.0
CRITICAL
EPSS
0.3%
2025 CWE-95 1 PoC

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

CVE-2025-45854
JEHC-BPM General ⚡ nuclei
10.0
CRITICAL
EPSS
21.4%
2025 CWE-862 0 PoCs

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

CVE-2025-66209
coolify General
10.0
CRITICAL
EPSS
0.2%
2025 CWE-78 1 PoC

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions to execute arbitrary commands as root on managed servers. Database names used in backup operations are passed directly to shell commands without sanitization, enabling full remote code execution. Version 4.0.0-beta.451 fixes the issue.

CVE-2025-34163
Dongsheng Logistics Software General
10.0
CRITICAL
EPSS
1.2%
2025 CWE-434 1 PoC

Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation and access control. An attacker can upload arbitrary files, including executable scripts such as .ashx, via a crafted multipart/form-data POST request. This allows remote code execution on the server, potentially leading to full system compromise. The vulnerability is presumed to affect builds released prior to July 2025 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined. Exploitation ev

CVE-2025-58321
DIALink General
10.0
CRITICAL
EPSS
0.1%
2025 CWE-22 1 PoC

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

CVE-2025-3322
OnlineSuite General
10.0
CRITICAL
EPSS
2.2%
2025 CWE-917 1 PoC

An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.

CVE-2025-32682
MapSVG General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through <= 8.6.4.

CVE-2025-20051
Mattermost General
9.9
CRITICAL
EPSS
0.3%
2025 CWE-22 1 PoC

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially crafted block in Boards.

CVE-2025-26892
Celestial Aura General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

CVE-2025-12419
Mattermost General
9.9
CRITICAL
EPSS
0.1%
2025 CWE-303 1 PoC

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system with one of them never having logged into Mattermost.

CVE-2025-46157
Software Genérico General
9.9
CRITICAL
EPSS
0.9%
2025 1 PoC

An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form

CVE-2025-30911
RTMKit General
9.9
CRITICAL
EPSS
1.7%
2025 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.

CVE-2025-30220
geoserver General ⚡ nuclei
9.9
CRITICAL
EPSS
13.9%
2025 CWE-611 0 PoCs

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used

CVE-2025-68668
n8n General
9.9
CRITICAL
EPSS
0.1%
2025 CWE-693 1 PoC

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit this vulnerability to execute arbitrary commands on the host system running n8n, using the same privileges as the n8n process. This issue has been patched in version 2.0.0. Workarounds for this issue involve disabling the Code Node by setting the environment variable NODES_EXCLUDE: "[\"n8n-nodes-base.code\"]", disabling Python support in the Code no

CVE-2025-4981
Mattermost General
9.9
CRITICAL
EPSS
1.7%
2025 CWE-427 1 PoC

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default.

CVE-2025-0867
SICK MEAC300 General
9.9
CRITICAL
EPSS
0.2%
2025 CWE-522 1 PoC

The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allows a privilege escalation to the administrative level.