5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-60991
Software Genérico Web
8.8
HIGH
EPSS
0.0%
2025 1 PoC

A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload injected into the cat parameter.

CVE-2025-12907
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-20 1 PoC

Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low)

CVE-2025-56099
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-YST AP_3.0(1)B11P280YST250F allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

CVE-2025-5280
Chrome General
8.8
HIGH
EPSS
0.6%
2025 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-56077
Software Genérico General
8.8
HIGH
EPSS
0.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVE-2025-53558
ZXHN-F660T General ⚡ nuclei
8.8
HIGH
EPSS
13.1%
2025 CWE-1391 0 PoCs

ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.

CVE-2025-59106
Access Manager 92xx-k7 General
8.8
HIGH
EPSS
0.1%
2025 CWE-272 2 PoCs

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

CVE-2025-51482
Software Genérico Web Networking ⚡ nuclei
8.8
HIGH
EPSS
5.8%
2025 2 PoCs

Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions.

CVE-2025-55345
Software Genérico General
8.8
HIGH
EPSS
0.5%
2025 CWE-61 1 PoC

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

CVE-2025-56127
Software Genérico General
8.8
HIGH
EPSS
1.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the get_wanobj in file /usr/lib/lua/luci/controller/admin/common.lua.

CVE-2025-34225
Print Virtual Appliance Host Web
8.8
HIGH
EPSS
0.4%
2025 CWE-306 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a server-side request forgery (SSRF) vulnerability. The `console_release` directory is reachable from the internet without any authentication. Inside that directory are dozens of PHP scripts that build URLs from user‑controlled values and then invoke either 'curl_exec()` or `file_get_contents()` without proper validation. Although many files attempt to mitigate SSRF by calling `filter_var', the checks are incomplete. Because the endpoin

CVE-2025-5068
Chrome General
8.8
HIGH
EPSS
0.4%
2025 CWE-416 1 PoC

Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-65573
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a denial of service via function handle_interface_POST_and_status.

CVE-2025-12429
Chrome General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVE-2025-35984
SAIL Image Decoding Library General
8.8
HIGH
EPSS
0.4%
2025 CWE-122 2 PoCs

A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a specially crafted .pcx file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

CVE-2025-13228
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-43953
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or traceroute field on the TCP/IP screen.

CVE-2025-66953
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2025 1 PoC

CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interface and specifically the /system_setup.htm, /set_clock.htm, /receiver_setup.htm, /cal.htm?..., and /channel_setup.htm endpoints

CVE-2025-32919
Checkmk Windows
8.8
HIGH
EPSS
0.0%
2025 CWE-427 1 PoC

Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all versions of 2.1.0 (EOL).

CVE-2025-48543
🔥 KEV Android General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.