2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-26399
🔥 KEV Web Help Desk General
9.8
CRITICAL
EPSS
26.6%
2025 CWE-502 2 PoCs

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

CVE-2025-49533
Adobe Experience Manager (MS) General ⚡ nuclei
9.8
CRITICAL
EPSS
76.4%
2025 CWE-502 0 PoCs

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

CVE-2025-41646
Revolution Pi webstatus General ⚡ nuclei
9.8
CRITICAL
EPSS
33.8%
2025 CWE-704 3 PoCs

An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device

CVE-2025-65552
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attacker within RF range to record valid alarm/control frames and replay them to trigger false alarms.

CVE-2025-4632
🔥 KEV MagicINFO 9 Server General ⚡ nuclei
9.8
CRITICAL
EPSS
49.2%
2025 CWE-22 1 PoC

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

CVE-2025-25362
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.

CVE-2025-24237
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.7%
2025 3 PoCs

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination.

CVE-2025-44885
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.

CVE-2025-44891
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.

CVE-2025-48005
libbiosig General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted RHS2000 file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-45813
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

CVE-2025-27678
Software Genérico General
9.8
CRITICAL
EPSS
4.6%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001.

CVE-2025-63213
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2025 1 PoC

The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the /cgi-bin/net_ping.cgi endpoint. An attacker can exploit this vulnerability by sending a specially crafted GET request with a malicious parameter to inject arbitrary commands. These commands are executed with root privileges, allowing attackers to gain full control over the device. This poses a significant security risk to any device running this software.

CVE-2025-24211
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.2%
2025 3 PoCs

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.

CVE-2025-29659
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2025 1 PoC

Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.

CVE-2025-27657
Software Genérico General
9.8
CRITICAL
EPSS
1.8%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.

CVE-2025-27682
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.

CVE-2025-49223
billboard.js General
9.8
CRITICAL
EPSS
0.8%
2025 CWE-1321 1 PoC

billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

CVE-2025-53118
Unified PAM General ⚡ nuclei
9.8
CRITICAL
EPSS
34.6%
2025 CWE-306 0 PoCs

An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.

CVE-2025-24260
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker in a privileged position may be able to perform a denial-of-service.