2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-70146
Software Genérico Web
9.1
CRITICAL
EPSS
0.6%
2025 1 PoC

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.

CVE-2025-28232
Software Genérico Web
9.1
CRITICAL
EPSS
0.2%
2025 1 PoC

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

CVE-2025-45953
Software Genérico Web
9.1
CRITICAL
EPSS
0.3%
2025 1 PoC

A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely

CVE-2025-15484
Order Notification for WooCommerce Web Windows
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

CVE-2025-63416
Software Genérico Web
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated low-privileged attackers to execute arbitrary JavaScript in the context of other users' sessions. This can be exploited to access administrative data and functions, leading to privilege escalation and full compromise of sensitive user data, as demonstrated by the ability to fetch and exfiltrate the contents of the /admin/users endpoint.

CVE-2025-25014
Kibana Web
9.1
CRITICAL
EPSS
2.5%
2025 CWE-1321 2 PoCs

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

CVE-2025-52390
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to manipulate the SQL logic and potentially extract sensitive information or escalate their privileges.

CVE-2025-8942
WP Hotel Booking Web Windows
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.

CVE-2025-5393
Alone – Charity Multipurpose Non-profit WordPress Theme Web Windows
9.1
CRITICAL
EPSS
0.9%
2025 CWE-73 1 PoC

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_restore_data() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This was partially patched in 7.8.5 and has been fully addresses in 7.8.7.

CVE-2025-66945
Software Genérico Web
9.1
CRITICAL
EPSS
0.2%
2025 1 PoC

A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outside the intended directory, leading to arbitrary file overwrite and potentially remote code execution

CVE-2025-14829
E-xact | Hosted Payment | Web Windows
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

CVE-2025-4603
eMagicOne Store Manager for WooCommerce Web Windows
9.1
CRITICAL
EPSS
3.0%
2025 CWE-73 3 PoCs

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is only exploitable by unauthenticated attackers in default configurations where the the default password is left as 1:1, or where the attacker gains access to the credentials.

CVE-2025-54309
🔥 KEV CrushFTP Web
9.0
CRITICAL
EPSS
77.8%
2025 CWE-420 10 PoCs

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

CVE-2025-22144
Nameless Web
9.0
CRITICAL
EPSS
0.4%
2025 CWE-610 1 PoC

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually validated by a user with admincp.core.emails or admincp.users.edit permissions then the reset_code will no longer be NULL but empty. An attacker can request http://localhost/nameless/index.php?route=/forgot_password/&c= and reset the password. As a result an attacker may compromi

CVE-2025-8264
z-push/z-push-dev Web Database Windows
9.0
CRITICAL
EPSS
0.1%
2025 CWE-89 1 PoC

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. This allows the attacker to access and potentially modify or delete sensitive data from a linked third-party database. **Note:** This vulnerability affects Z-Push installations that utilize the IMAP backend and have the IMAP_FROM_SQL_QUERY option configured. Mitigation Change configuration to use the default or LDAP in backend/imap/config.php php defi

CVE-2025-48828
vBulletin Web ⚡ nuclei
9.0
CRITICAL
EPSS
73.7%
2025 CWE-424 3 PoCs

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.

CVE-2025-56795
Software Genérico Web
9.0
CRITICAL
EPSS
0.1%
2025 1 PoC

Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.

CVE-2025-50067
Oracle Application Express Web Database
9.0
CRITICAL
EPSS
0.2%
2025 1 PoC

Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Express. CVSS

CVE-2025-9501
W3 Total Cache Web Windows
9.0
CRITICAL
EPSS
2.9%
2025 1 PoC

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

CVE-2025-11957
Server Web
9.0
CRITICAL
EPSS
0.1%
2025 CWE-639 1 PoC

Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.