2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-9286
Appy Pie Connect for WooCommerce Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 CWE-620 1 PoC

The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to reset the password of arbitrary users, including administrators, thereby gaining administrative access.

CVE-2025-5394
Alone – Charity Multipurpose Non-profit WordPress Theme Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
17.5%
2025 CWE-862 4 PoCs

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. CVE-2025-54019 is likely a duplicate of this.

CVE-2025-45065
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 3 PoCs

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

CVE-2025-52122
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

CVE-2025-7437
Ebook Store Web Windows
9.8
CRITICAL
EPSS
0.7%
2025 CWE-434 1 PoC

The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-43995
Dell Storage Manager Web
9.8
CRITICAL
EPSS
0.2%
2025 CWE-287 1 PoC

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.

CVE-2025-26319
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
88.7%
2025 3 PoCs

FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

CVE-2025-46189
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.

CVE-2025-36846
Software Genérico Web
9.8
CRITICAL
EPSS
50.1%
2025 1 PoC

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec() function of PHP. NOTE: this can be chained with CVE-2025-36845.

CVE-2025-15559
WorkTime (on-prem/cloud) Web Cloud
9.8
CRITICAL
EPSS
0.2%
2025 CWE-78 1 PoC

An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from the WorkTime server is vulnerable in the “guid” parameter. This allows an attacker to execute arbitrary commands on the WorkTime server as NT Authority\SYSTEM with the highest privileges. Attackers are able to access or manipulate sensitive data and take over the whole server.

CVE-2025-4094
DIGITS: WordPress Mobile Number Signup and Login Web Windows
9.8
CRITICAL
EPSS
3.0%
2025 3 PoCs

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.

CVE-2025-8047
disable-right-click-powered-by-pixterme Web Cloud Windows
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup.

CVE-2025-4524
Madara – Responsive and modern WordPress theme for manga sites Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
16.5%
2025 CWE-22 2 PoCs

The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2025-65354
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise.

CVE-2025-1974
ingress-nginx DevOps Web ⚡ nuclei
9.8
CRITICAL
EPSS
91.1%
2025 CWE-653 18 PoCs

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVE-2025-27649
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Access Control: PHP V-2023-016.

CVE-2025-50707
Software Genérico Web
9.8
CRITICAL
EPSS
1.7%
2025 1 PoC

An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

CVE-2025-13595
CIBELES AI Web Windows
9.8
CRITICAL
EPSS
0.6%
2025 CWE-434 2 PoCs

The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.10.8. This makes it possible for unauthenticated attackers to download arbitrary GitHub repositories and overwrite plugin files on the affected site's server which may make remote code execution possible.

CVE-2025-5304
PT Project Notebooks – Take Meeting minutes, create budgets, track task management, and more Web Windows
9.8
CRITICAL
EPSS
1.3%
2025 CWE-862 1 PoC

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVE-2025-44022
Software Genérico Web
9.8
CRITICAL
EPSS
4.5%
2025 1 PoC

An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.