5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-53770
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.5%
2025 CWE-502 46 PoCs

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

CVE-2025-66045
libbiosig General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-121 1 PoC

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 65

CVE-2025-3365
OnlineSuite General
9.8
CRITICAL
EPSS
0.7%
2025 CWE-23 1 PoC

A missing protection against path traversal allows to access any file on the server.

CVE-2025-32814
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
32.1%
2025 0 PoCs

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

CVE-2025-44898
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.

CVE-2025-28138
Software Genérico General
9.8
CRITICAL
EPSS
3.8%
2025 2 PoCs

The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

CVE-2025-24265
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

CVE-2025-24204
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVE-2025-15030
User Profile Builder Web Windows
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

CVE-2025-28411
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

CVE-2025-45777
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request.

CVE-2025-52376
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security controls. The Telnet server is then accessible with hard-coded credentials, allowing attackers to gain administrative shell access and execute arbitrary commands on the device.

CVE-2025-28238
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.

CVE-2025-66678
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request.

CVE-2025-69633
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized to SQL queries in classes/AdvancedPopup.php (getPopups() and updateVisits() functions).

CVE-2025-52122
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

CVE-2025-44886
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.

CVE-2025-54484
libbiosig General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability manifests on line 8779 of biosig.c on the current master branch (35a819fa), when the Tag is 6: else if (tag==6) // 0x06 "number of sequences" { // NRec if (len>4) fprintf(stderr,"Warning MFER tag6 incorrect length %i>4\n",len); curPos += ifread(buf,1,len,hdr

CVE-2025-44148
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
14.5%
2025 1 PoC

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

CVE-2025-44136
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
13.0%
2025 1 PoC

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.