33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-27007
OttoKit General ⚡ nuclei
9.8
CRITICAL
EPSS
81.5%
2025 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.

CVE-2025-65570
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array element access as the left-hand operand inside a for-in loop, the instructions implementation leaves an additional array reference on the stack rather than consuming it during OP_INSTANCEOF. As a result, OP_NEXT interprets the array as an iterator object and reads the iterCmd function pointer from an invalid structure, potentially causing a crash or enabling code execution depending on heap layout.

CVE-2025-31201
🔥 KEV iOS and iPadOS General
9.8
CRITICAL
EPSS
2.3%
2025 1 PoC

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

CVE-2025-47646
PSW Front-end Login & Registration General ⚡ nuclei
9.8
CRITICAL
EPSS
8.9%
2025 CWE-640 2 PoCs

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.

CVE-2025-50428
Software Genérico Web
9.8
CRITICAL
EPSS
2.3%
2025 2 PoCs

In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.

CVE-2025-61455
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorporates unsanitized user inputs into SQL queries, allowing unauthenticated attackers to bypass authentication and gain full access.

CVE-2025-29165
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component

CVE-2025-47539
Eventin General ⚡ nuclei
9.8
CRITICAL
EPSS
27.9%
2025 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.

CVE-2025-11953
🔥 KEV Software Genérico Windows
9.8
CRITICAL
EPSS
18.6%
2025 CWE-78 1 PoC

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

CVE-2025-31183
iOS and iPadOS DevOps
9.8
CRITICAL
EPSS
0.3%
2025 2 PoCs

The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

CVE-2025-2294
Kubio AI Page Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
69.2%
2025 CWE-22 8 PoCs

The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2025-46060
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2025 1 PoC

Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component

CVE-2025-56221
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.

CVE-2025-0074
Android General
9.8
CRITICAL
EPSS
1.8%
2025 1 PoC

In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-5099
PrinterShare Mobile Print General
9.8
CRITICAL
EPSS
1.0%
2025 CWE-119 1 PoC

An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution.

CVE-2025-30462
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Apps that appear to use App Sandbox may be able to launch without restrictions.

CVE-2025-13595
CIBELES AI Web Windows
9.8
CRITICAL
EPSS
0.6%
2025 CWE-434 2 PoCs

The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.10.8. This makes it possible for unauthenticated attackers to download arbitrary GitHub repositories and overwrite plugin files on the affected site's server which may make remote code execution possible.

CVE-2025-28236
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2025 1 PoC

Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package to the /#/software/upgrades endpoint.

CVE-2025-66046
libbiosig General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-121 1 PoC

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 67

CVE-2025-4606
Sala - Startup & SaaS WordPress Theme Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 CWE-620 2 PoCs

The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.4. This is due to the theme not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.