2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-31361
BCM5820X Web
8.7
HIGH
EPSS
0.0%
2025 CWE-908 1 PoC

A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to privilege escalation. An attacker can issue an api call to trigger this vulnerability.

CVE-2025-7054
quiche Web Cloud
8.7
HIGH
EPSS
0.1%
2025 CWE-835 2 PoCs

Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000 https://datatracker.ietf.org/doc/html/rfc9000#section-5.1 . Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers. An una

CVE-2025-60503
Software Genérico Web
8.7
HIGH
EPSS
0.0%
2025 1 PoC

A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session, which could lead to session hijacking or other malicious actions.

CVE-2025-41373
Gandia Integra Total Web Database
8.7
HIGH
EPSS
0.1%
2025 CWE-89 1 PoC

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php.

CVE-2025-4826
A702R Web
8.7
HIGH
EPSS
1.0%
2025 CWE-120 1 PoC

A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-34115
OP5 Monitor Web
8.7
HIGH
EPSS
70.7%
2025 CWE-78 2 PoCs

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user. The vulnerability resides in the configuration section of the application and requires valid login credentials with access to the command testing functionality. This issue is fixed in version 7.2.0.

CVE-2025-34031
Jmol Plugin Web ⚡ nuclei
8.7
HIGH
EPSS
18.3%
2025 CWE-22 2 PoCs

A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from the server's filesystem by crafting a malicious query value. This vulnerability can be exploited without authentication and may expose sensitive configuration data, including database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.

CVE-2025-34517
EVE X1 Server Web
8.7
HIGH
EPSS
0.1%
2025 CWE-22 1 PoC

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

CVE-2025-7465
FH1201 Web
8.7
HIGH
EPSS
1.1%
2025 CWE-120 1 PoC

A vulnerability classified as critical was found in Tenda FH1201 1.2.0.14. Affected by this vulnerability is the function fromRouteStatic of the file /goform/fromRouteStatic of the component HTTP POST Request Handler. The manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8110
🔥 KEV Gogs Web ⚡ nuclei
8.7
HIGH
EPSS
17.7%
2025 CWE-22 1 PoC

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

CVE-2025-0669
BOINC Server Web
8.6
HIGH
EPSS
0.1%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOINC Server: before 1.4.3.

CVE-2025-55150
Stirling-PDF Web ⚡ nuclei
8.6
HIGH
EPSS
6.1%
2025 CWE-918 0 PoCs

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitization which can be bypassed and result in SSRF. This issue has been patched in version 1.1.0.

CVE-2025-12061
TAX SERVICE Electronic HDM Web Database Windows
8.6
HIGH
EPSS
0.0%
2025 1 PoC

The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements

CVE-2025-66024
application-blog-ui Web
8.6
HIGH
EPSS
0.9%
2025 CWE-79 1 PoC

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arises because the post title is injected directly into the HTML <title> tag without proper escaping. An attacker with permissions to create or edit blog posts can inject malicious JavaScript into the title field. This script will execute in the browser of any user (including administrators) who views the blog post. This leads to potential session hijacking or privilege escalation.

CVE-2025-34506
WBCE CMS Web
8.6
HIGH
EPSS
0.7%
2025 CWE-434 1 PoC

WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.

CVE-2025-24801
glpi Web
8.6
HIGH
EPSS
3.0%
2025 CWE-434 2 PoCs

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.

CVE-2025-59932
flagForge Web
8.6
HIGH
EPSS
0.1%
2025 CWE-284 1 PoC

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1.

CVE-2025-8083
Vuetify Web
8.6
HIGH
EPSS
0.2%
2025 CWE-1321 4 PoCs

The Preset configuration https://v2.vuetifyjs.com/en/features/presets  feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html  due to the internal 'mergeDeep' utility function used to merge options with defaults. Using a specially-crafted, malicious preset can result in polluting all JavaScript objects with arbitrary properties, which can further negatively affect all aspects of the application's behavior. This can lead to a wide range of security issues, including resource exhaustion/denial of se

CVE-2025-49181
SICK Media Server Web
8.6
HIGH
EPSS
0.6%
2025 CWE-862 1 PoC

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack.

CVE-2025-45997
Software Genérico Web
8.6
HIGH
EPSS
0.7%
2025 2 PoCs

Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.