5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-41706
QUINT4-UPS/24DC/24DC/5/EIP General
5.3
MEDIUM
EPSS
0.2%
2025 CWE-120 1 PoC

The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET request with an over-long content-length to trigger the issue without affecting the core functionality.

CVE-2025-4302
Stop User Enumeration Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
1.1%
2025 1 PoC

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

CVE-2025-6880
Best Salon Management System Web Database
5.3
MEDIUM
EPSS
0.3%
2025 CWE-89 1 PoC

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-tax.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-10593
Online Student File Management System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

CVE-2025-11237
Make Email Customizer for WooCommerce Web Windows
5.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.

CVE-2025-12933
Baby Care System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument roleid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

CVE-2025-6860
Best Salon Management System Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 2 PoCs

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/staff_commision.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-3817
Online Eyewear Shop Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /oews/classes/Master.php?f=delete_stock. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8157
User Registration & Login and User Management Web Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was found in PHPGurukul User Registration & Login and User Management 3.3. It has been classified as critical. This affects an unknown part of the file /admin/lastthirtyays-reg-users.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-14155
Premium Addons for Elementor – Powerful Elementor Templates & Widgets Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
0.7%
2025 CWE-862 1 PoC

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.

CVE-2025-7543
User Registration & Login and User Management System Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3. It has been classified as critical. This affects an unknown part of the file /admin/manage-users.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-9808
The Events Calendar Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
1.2%
2025 CWE-200 0 PoCs

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.

CVE-2025-14731
Content Management System Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-1336 2 PoCs

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-7158
Zoo Management System Web Database
5.3
MEDIUM
EPSS
0.3%
2025 CWE-89 1 PoC

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/manage-normal-ticket.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-2709
UFIDA ERP-NC General ⚡ nuclei
5.3
MEDIUM
EPSS
0.2%
2025 CWE-79 0 PoCs

A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation of the argument key/redirect leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-6874
Best Salon Management System Web Database
5.3
MEDIUM
EPSS
0.3%
2025 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/add_subscribe.php. The manipulation of the argument user_id/plan_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-10278
ruoyi-vue-pro General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-41679
mbNET.mini General
5.3
MEDIUM
EPSS
0.2%
2025 CWE-787 1 PoC

An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service.

CVE-2025-0795
CDG General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the file /todolistjump.jsp. The manipulation of the argument flowId leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-14434
Ultimate Post Kit Addons for Elementor Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and retrieve rendered HTML content of private and unpublished ones.