5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-34186
EVE X1/X5 Server General
9.3
CRITICAL
EPSS
0.8%
2025 CWE-287 1 PoC

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.

CVE-2025-34117
Router firmware Networking
9.3
CRITICAL
EPSS
50.3%
2025 CWE-912 4 PoCs

A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented. An unauthenticated remote attacker can send specially crafted UDP packets to execute arbitrary commands on the affected device. This backdoor uses a hardcoded authentication mechanism and accepts shell commands post-authentication. Some device models include a non-standard implementation of the `echo` command, which may affect exploitability.

CVE-2025-8890
NE6037 Networking
9.3
CRITICAL
EPSS
0.3%
2025 CWE-78 1 PoC

Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks. In order to exploit this vulnerability, an attacker has to log in to the router's administrative portal, which by default is reachable only via LAN ports.

CVE-2025-59367
DSL-AC51 Networking
9.3
CRITICAL
EPSS
0.2%
2025 CWE-288 1 PoC

An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.

CVE-2025-34110
Server Windows
9.3
CRITICAL
EPSS
50.6%
2025 CWE-22 2 PoCs

A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in the FTP GET and PUT command handlers. Exploitation is possible by submitting traversal sequences during FTP operations, enabling access to system-sensitive files. This issue affects only the Windows version of ColoradoFTP.

CVE-2025-11849
mammoth General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-22 4 PoCs

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker ca

CVE-2025-34192
Print Virtual Appliance Host Cloud
9.3
CRITICAL
EPSS
0.6%
2025 CWE-1104 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to 20.0.2140 (macOS/Linux client deployments) are built against OpenSSL 1.0.2h-fips (released May 2016), which has been end-of-life since 2019 and is no longer supported by the OpenSSL project. Continued use of this outdated cryptographic library exposes deployments to known vulnerabilities that are no longer patched, weakening the overall security posture. Affected daemons may emit deprecation warnings and rely on cryptographic components with unresolved security flaws, potent

CVE-2025-32013
lnbits Web
9.3
CRITICAL
EPSS
0.1%
2025 CWE-918 1 PoC

LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn't properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.

CVE-2025-7850
Omada gateways General
9.3
CRITICAL
EPSS
1.0%
2025 CWE-78 1 PoC

A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

CVE-2025-2776
🔥 KEV SysAid On-Prem General ⚡ nuclei
9.3
CRITICAL
EPSS
62.6%
2025 CWE-611 2 PoCs

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

CVE-2025-34101
Media Server Web Windows
9.3
CRITICAL
EPSS
68.8%
2025 CWE-78 2 PoCs

An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoint exposed by the console component (default port 23423). The checkStreamUrl method accepts a VIDEO parameter that is passed unsanitized to a call to cmd.exe, enabling arbitrary command execution under the privileges of the web server. No authentication is required to exploit this issue, as the REST API is exposed by default and lacks access controls.

CVE-2025-32711
Microsoft 365 Copilot General
9.3
CRITICAL
EPSS
10.7%
2025 CWE-74 1 PoC

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2025-27593
SICK DL100-2xxxxxxx General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-494 1 PoC

The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems.

CVE-2025-15113
lares General
9.3
CRITICAL
EPSS
0.0%
2025 CWE-256 1 PoC

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.

CVE-2025-32434
pytorch General
9.3
CRITICAL
EPSS
1.2%
2025 CWE-502 1 PoC

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.

CVE-2025-34100
CMS Web
9.3
CRITICAL
EPSS
79.3%
2025 CWE-434 5 PoCs

An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php file and subsequently execute arbitrary PHP code on the server under the context of the web server process. While the root vulnerability lies within the jQuery File Upload component, BuilderEngine’s improper integration and lack of access controls expose this functionality to unau

CVE-2025-41426
Liebert RDU101 General
9.3
CRITICAL
EPSS
0.9%
2025 CWE-121 1 PoC

Affected Vertiv products contain a stack based buffer overflow vulnerability. An attacker could exploit this vulnerability to gain code execution on the device.

CVE-2025-25037
Aquatronica Controller System Web ⚡ nuclei
9.3
CRITICAL
EPSS
2.1%
2025 CWE-200 2 PoCs

An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.

CVE-2025-59090
Kaba exos 9300 Web
9.3
CRITICAL
EPSS
0.1%
2025 CWE-306 2 PoCs

On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as well as querying the 2FA PINs associated with the enrolled chip cards.

CVE-2025-34127
Achat Chat Server General
9.3
CRITICAL
EPSS
56.3%
2025 CWE-121 2 PoCs

A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-supplied input leading to remote code execution.