5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-27680
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmware Image with Insufficient Verification of Data Authenticity V-2024-004.

CVE-2025-39436
I Draw General
9.1
CRITICAL
EPSS
0.1%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0.

CVE-2025-46122
Software Genérico Web
9.1
CRITICAL
EPSS
0.5%
2025 1 PoC

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.

CVE-2025-46117
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 1 PoC

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controller or specified target.

CVE-2025-50251
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.

CVE-2025-66945
Software Genérico Web
9.1
CRITICAL
EPSS
0.2%
2025 1 PoC

A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outside the intended directory, leading to arbitrary file overwrite and potentially remote code execution

CVE-2025-47202
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2025 2 PoCs

In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, the lack of a length check leads to out-of-bounds writes.

CVE-2025-49029
Custom Login And Signup Widget General ⚡ nuclei
9.1
CRITICAL
EPSS
0.7%
2025 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0.

CVE-2025-25014
Kibana Web
9.1
CRITICAL
EPSS
2.5%
2025 CWE-1321 2 PoCs

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

CVE-2025-47549
BEAF General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Upload a Web Shell to a Web Server.This issue affects BEAF: from n/a through <= 4.6.10.

CVE-2025-54677
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
9.1
CRITICAL
EPSS
0.1%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Malicious Files.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.3.

CVE-2025-46271
UNI-NMS-Lite General
9.1
CRITICAL
EPSS
5.7%
2025 CWE-78 1 PoC

UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

CVE-2025-28230
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 1 PoC

Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.

CVE-2025-65319
Software Genérico Windows
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.

CVE-2025-22604
cacti General
9.1
CRITICAL
EPSS
70.5%
2025 CWE-78 1 PoC

Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as part of a system command, causing a command execution vulnerability. This vulnerability is fixed in 1.2.29.

CVE-2025-54236
🔥 KEV Adobe Commerce General ⚡ nuclei
9.1
CRITICAL
EPSS
64.8%
2025 CWE-20 1 PoC

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

CVE-2025-22940
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 2 PoCs

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

CVE-2025-32118
CMP – Coming Soon & Maintenance General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.

CVE-2025-15484
Order Notification for WooCommerce Web Windows
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

CVE-2025-51535
Software Genérico Database
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.