2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-51970
Software Genérico Web Database
7.7
HIGH
EPSS
0.0%
2025 2 PoCs

A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.

CVE-2025-10635
Find Me On Web Database Windows
7.7
HIGH
EPSS
0.0%
2025 1 PoC

The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks

CVE-2025-0626
CMS8000 Patient Monitor Web
7.7
HIGH
EPSS
0.1%
2025 CWE-912 1 PoC

The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function also enables the network interface of the device if it is disabled. The function is triggered by attempting to update the device from the user menu. This could serve as a backdoor to the device, and could lead to a malicious actor being able to upload and overwrite files on the device.

CVE-2025-46822
Java-springboot-codebase Web ⚡ nuclei
7.7
HIGH
EPSS
6.8%
2025 CWE-36 1 PoC

OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive internal files. Commit c835c6f7799eacada4c0fc77e0816f250af01ad2 contains a patch for the issue.

CVE-2025-0107
Cloud NGFW Web Networking Cloud ⚡ nuclei
7.7
HIGH
EPSS
79.5%
2025 CWE-78 0 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

CVE-2025-27152
axios Web
7.7
HIGH
EPSS
0.2%
2025 CWE-918 1 PoC

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.

CVE-2025-13000
db-access Web Database Windows
7.7
HIGH
EPSS
0.0%
2025 1 PoC

The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks

CVE-2025-14804
Frontend File Manager Plugin Web Windows
7.7
HIGH
EPSS
0.0%
2025 1 PoC

The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server

CVE-2025-5115
Eclipse Jetty Web
7.7
HIGH
EPSS
0.2%
2025 CWE-400 1 PoC

In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory. For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client

CVE-2025-13523
Mattermost Confluence Plugin Web
7.7
HIGH
EPSS
0.0%
2025 CWE-79 1 PoC

Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557

CVE-2025-2610
MagnusBilling Web ⚡ nuclei
7.6
HIGH
EPSS
1.6%
2025 CWE-79 1 PoC

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.

CVE-2025-59461
TLOC100-100 all Firmware versions Web
7.6
HIGH
EPSS
0.1%
2025 CWE-862 1 PoC

A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

CVE-2025-46349
yeswiki Web ⚡ nuclei
7.6
HIGH
EPSS
0.5%
2025 CWE-79 0 PoCs

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patched in version 4.5.4.

CVE-2025-4123
Grafana DevOps Web ⚡ nuclei
7.6
HIGH
EPSS
5.3%
2025 CWE-79 10 PoCs

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVE-2025-51503
Software Genérico Web
7.6
HIGH
EPSS
0.2%
2025 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

CVE-2025-45805
Software Genérico Web
7.6
HIGH
EPSS
0.0%
2025 1 PoC

In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.

CVE-2025-29152
Software Genérico Web
7.6
HIGH
EPSS
0.3%
2025 2 PoCs

Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple components, including Strategic Planning Perspective Registration, Training Request, Perspective Editing, Education Registration, Hierarchical Level Registration, Decision Level Registration, Perspective Registration, Company Group Registration, Company Registration, News Registration, Employee Editing, Goal Team Registration, Learning Resource Type Registration, Learning Resource Family Registration, Learning Resource Supplier Registration, and Cycle Maintena

CVE-2025-51504
Software Genérico Web
7.6
HIGH
EPSS
0.1%
2025 1 PoC

Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.

CVE-2025-71031
Software Genérico Web
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maximum length. As a result, an excessive request header could cause a denial of service by consuming RAM memory.

CVE-2025-49125
Apache Tomcat Web
7.5
HIGH
EPSS
0.3%
2025 CWE-288 1 PoC

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are