13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-65518
Software Genérico Web
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.

CVE-2025-62771
M6a Web
7.5
HIGH
EPSS
0.0%
2025 CWE-352 1 PoC

Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.

CVE-2025-1323
WP-Recall – Registration, Profile, Commerce & More Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
27.3%
2025 CWE-89 1 PoC

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-66905
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.

CVE-2025-60574
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.

CVE-2025-25231
Omnissa Workspace ONE UEM Web ⚡ nuclei
7.5
HIGH
EPSS
4.0%
2025 1 PoC

Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.

CVE-2025-49125
Apache Tomcat Web
7.5
HIGH
EPSS
0.3%
2025 CWE-288 1 PoC

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are

CVE-2025-41248
Spring Security Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is pu

CVE-2025-61884
🔥 KEV Oracle Configurator Web Database ⚡ nuclei
7.5
HIGH
EPSS
48.3%
2025 3 PoCs

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2025-7442
WPGYM - Wordpress Gym Management System Web Database Windows
7.5
HIGH
EPSS
0.3%
2025 CWE-89 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters in the MJ_gmgt_delete_class_limit_for_member, MJ_gmgt_get_yearly_income_expense, MJ_gmgt_get_monthly_income_expense, MJ_gmgt_add_class_limit, MJ_gmgt_view_meeting_detail, and MJ_gmgt_create_meeting functions in all versions up to 67.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that

CVE-2025-1361
IP2Location Country Blocker Web Windows ⚡ nuclei
7.5
HIGH
EPSS
8.3%
2025 CWE-285 0 PoCs

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

CVE-2025-50490
Software Genérico Web
7.5
HIGH
EPSS
0.2%
2025 1 PoC

Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

CVE-2025-56589
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HTML2PDF SDK thru 11.6.0. These vulnerabilities could allow an attacker to read local files on the server or make arbitrary HTTP requests to internal or external services. Both vulnerabilities could lead to the disclosure of sensitive data or potential system takeover.

CVE-2025-49183
SICK Media Server Web
7.5
HIGH
EPSS
0.2%
2025 CWE-319 1 PoC

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.

CVE-2025-5920
Sharable Password Protected Posts Web
7.5
HIGH
EPSS
0.3%
2025 1 PoC

The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.

CVE-2025-59049
mockoon Web Cloud ⚡ nuclei
7.5
HIGH
EPSS
1.9%
2025 CWE-73 0 PoCs

Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach presented in the documentation page, where the server filename is generated via templating features from user input is vulnerable to Path Traversal and LFI, allowing an attacker to get any file in the mock server filesystem. The issue may be particularly relevant in cloud hosted server instances. Version 9.2.0 fixes the issue.

CVE-2025-63955
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).

CVE-2025-66723
Software Genérico Web
7.5
HIGH
EPSS
0.0%
2025 1 PoC

inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths.

CVE-2025-48957
AstrBot Web
7.5
HIGH
EPSS
1.1%
2025 CWE-23 2 PoCs

AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has been addressed in Pull Request #1676 and is included in version 3.5.13. As a workaround, users can edit the `cmd_config.json` file to disable the dashboard feature as a temporary workaround. However, it is strongly recommended to upgrade to version v3.5.13 or later to fully resolve this issue.

CVE-2025-59802
Software Genérico Web
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF triggers to dynamically change the visibility of OCG content after signing (Post-Sign), allowing the visual content of a signed PDF to be modified without invalidating the signature. This may result in a mismatch between the signed content and what the signer or verifier sees, undermining the trustworthiness of the digit