2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-28407
Software Genérico General
8.8
HIGH
EPSS
0.7%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId

CVE-2025-14766
Chrome General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-56113
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

CVE-2025-53772
Web Deploy 4.0 General
8.8
HIGH
EPSS
11.1%
2025 CWE-502 3 PoCs

Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

CVE-2025-65817
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.

CVE-2025-52089
Software Genérico General
8.8
HIGH
EPSS
3.2%
2025 1 PoC

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.

CVE-2025-56095
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVE-2025-31129
jooby General
8.8
HIGH
EPSS
0.5%
2025 CWE-502 1 PoC

Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 (3.x).

CVE-2025-55345
Software Genérico General
8.8
HIGH
EPSS
0.5%
2025 CWE-61 1 PoC

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

CVE-2025-0592
SICK Lector8xx General
8.8
HIGH
EPSS
0.1%
2025 CWE-924 1 PoC

The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device.

CVE-2025-52930
SAIL Image Decoding Library General
8.8
HIGH
EPSS
0.4%
2025 CWE-680 2 PoCs

A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially crafted .bmp file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

CVE-2025-56093
Software Genérico General
8.8
HIGH
EPSS
0.5%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless.lua.

CVE-2025-55164
content-security-policy-parser General
8.8
HIGH
EPSS
0.2%
2025 CWE-1321 1 PoC

content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This issue has been patched in version 0.6.0. A workaround involves disabling prototype method in NodeJS, neutralizing all possible prototype pollution attacks. Provide either --disable-proto=delete (recommended) or --disable-proto=throw as an argument to node to enable this feature.

CVE-2025-5068
Chrome General
8.8
HIGH
EPSS
0.4%
2025 CWE-416 1 PoC

Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-9132
Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-56107
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config.lua.

CVE-2025-1918
Chrome General
8.8
HIGH
EPSS
0.7%
2025 CWE-125 1 PoC

Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Medium)

CVE-2025-23093
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges.

CVE-2025-21064
Smart Switch General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

CVE-2025-5958
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)