5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-1919
Chrome General
8.8
HIGH
EPSS
0.7%
2025 CWE-125 1 PoC

Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-56094
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/host_access_delay.lua.

CVE-2025-26210
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2025 2 PoCs

DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.

CVE-2025-53558
ZXHN-F660T General ⚡ nuclei
8.8
HIGH
EPSS
13.1%
2025 CWE-1391 0 PoCs

ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.

CVE-2025-65730
Software Genérico General
8.8
HIGH
EPSS
0.4%
2025 1 PoC

Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication.

CVE-2025-56095
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVE-2025-4954
Axle Demo Importer Web Windows
8.8
HIGH
EPSS
0.4%
2025 1 PoC

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

CVE-2025-1920
Chrome General
8.8
HIGH
EPSS
0.4%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-2249
SoJ SoundSlides Web Windows
8.8
HIGH
EPSS
0.9%
2025 CWE-434 1 PoC

The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-25614
Software Genérico General
8.8
HIGH
EPSS
0.4%
2025 1 PoC

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

CVE-2025-69784
Software Genérico General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an attacker-controlled DLL into high-privilege processes. This results in arbitrary code execution with SYSTEM privileges, leading to full compromise of the affected system.

CVE-2025-10200
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVE-2025-8882
Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-416 1 PoC

Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-3914
Aeropage Sync for Airtable Web Windows
8.8
HIGH
EPSS
3.1%
2025 CWE-434 1 PoC

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-63748
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2025 1 PoC

QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, which executes the PHP payload on the server.

CVE-2025-34511
Powershell Extension Web
8.8
HIGH
EPSS
85.8%
2025 CWE-434 1 PoC

Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.

CVE-2025-8011
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-62549
Windows 10 Version 1607 Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-822 2 PoCs

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-57457
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 2 PoCs

An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter.

CVE-2025-13630
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)