5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-39946
Linux General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are bogus Normally we wait for the socket to buffer up the whole record before we service it. If the socket has a tiny buffer, however, we read out the data sooner, to prevent connection stalls. Make sure that we abort the connection when we find out late that the record is actually invalid. Retrying the parsing is fine in itself but since we copy some more data each time before we parse we can overflow the allocated skb space. Constructing a scenario in which we're under pressu

CVE-2025-30430
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. Password autofill may fill in passwords after failing authentication.

CVE-2025-30113
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and 9092. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.

CVE-2025-45777
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request.

CVE-2025-24233
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to read or write to protected files.

CVE-2025-22403
Android General
9.8
CRITICAL
EPSS
2.3%
2025 1 PoC

In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-55583
Software Genérico Web Networking
9.8
CRITICAL
EPSS
1.5%
2025 1 PoC

D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or authentication. Remote attackers can exploit this to execute arbitrary commands as root via crafted HTTP requests.

CVE-2025-2005
Front End Users Web Windows
9.8
CRITICAL
EPSS
1.5%
2025 CWE-434 3 PoCs

The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-1066
OpenPLC General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.

CVE-2025-50165
Windows 11 Version 24H2 Windows
9.8
CRITICAL
EPSS
6.2%
2025 CWE-822 1 PoC

Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2025-27650
Software Genérico DevOps
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Private Keys in Docker Overlay V-2023-013.

CVE-2025-65834
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulated width and height parameters. By setting these values to extremely large numbers, the application attempts to allocate excessive memory during image processing, triggering a buffer overflow in the mlt_image_fill_white function.

CVE-2025-57118
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php

CVE-2025-24195
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to elevate privileges.

CVE-2025-25467
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.

CVE-2025-46188
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.

CVE-2025-5319
DIGITA Efficiency Management System Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System allows SQL Injection.This issue affects DIGITA Efficiency Management System: through 03022026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-65791
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier because there is no unsanitized user input to web/views/image.php.