5623 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-32880
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2025 3 PoCs

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication is not encrypted and allows sniffing and machine-in-the-middle attacks.

CVE-2025-70152
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.

CVE-2025-61757
🔥 KEV Identity Manager Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
87.8%
2025 1 PoC

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2025-25763
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

CVE-2025-31161
🔥 KEV CrushFTP Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
86.2%
2025 CWE-305 20 PoCs

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible with S3) authorization method of the HTTP component of the FTP server. The server first verifies the existence of the user by performing a call to login_user_pass() with no password requirement. This will authenticate the session through the HMAC verification process and up until the server checks f

CVE-2025-55575
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with action=service_detail.

CVE-2025-44658
Software Genérico Web
9.8
CRITICAL
EPSS
0.5%
2025 1 PoC

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.

CVE-2025-31651
Apache Tomcat Web
9.8
CRITICAL
EPSS
0.4%
2025 CWE-116 1 PoC

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL vers

CVE-2025-10294
OwnID Passwordless Login Web Windows
9.8
CRITICAL
EPSS
0.5%
2025 CWE-288 2 PoCs

The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to log in as other users, including administrators, on instances where the plugin has not been fully configured yet.

CVE-2025-4094
DIGITS: WordPress Mobile Number Signup and Login Web Windows
9.8
CRITICAL
EPSS
3.0%
2025 3 PoCs

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.

CVE-2025-0180
WP Foodbakery Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 CWE-269 1 PoC

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.

CVE-2025-50428
Software Genérico Web
9.8
CRITICAL
EPSS
2.3%
2025 2 PoCs

In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.

CVE-2025-61455
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorporates unsanitized user inputs into SQL queries, allowing unauthenticated attackers to bypass authentication and gain full access.

CVE-2025-2294
Kubio AI Page Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
69.2%
2025 CWE-22 8 PoCs

The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2025-13595
CIBELES AI Web Windows
9.8
CRITICAL
EPSS
0.6%
2025 CWE-434 2 PoCs

The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.10.8. This makes it possible for unauthenticated attackers to download arbitrary GitHub repositories and overwrite plugin files on the affected site's server which may make remote code execution possible.

CVE-2025-4606
Sala - Startup & SaaS WordPress Theme Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 CWE-620 2 PoCs

The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.4. This is due to the theme not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

CVE-2025-7401
Premium Age Verification / Restriction for WordPress Web Windows
9.8
CRITICAL
EPSS
1.9%
2025 CWE-798 1 PoC

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVE-2025-2907
Order Delivery Date Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
9.8%
2025 2 PoCs

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover.

CVE-2025-46188
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.

CVE-2025-50578
Software Genérico Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
2.4%
2025 1 PoC

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the applica