5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-1930
Firefox Windows
8.8
HIGH
EPSS
0.3%
2025 1 PoC

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-1006
Chrome General
8.8
HIGH
EPSS
0.6%
2025 CWE-416 1 PoC

Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. (Chromium security severity: Medium)

CVE-2025-56107
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config.lua.

CVE-2025-50110
Software Genérico Web
8.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS

CVE-2025-59684
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.

CVE-2025-56085
Software Genérico General
8.8
HIGH
EPSS
0.6%
2025 2 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

CVE-2025-56108
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

CVE-2025-7049
WPGYM - Wordpress Gym Management System Web Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-639 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_add_user' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the email, password, and other details of any user, including Administrator users.

CVE-2025-32089
BCM5820X Web
8.8
HIGH
EPSS
0.0%
2025 CWE-120 1 PoC

A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to a arbitrary code execution. An attacker can issue an api call to trigger this vulnerability.

CVE-2025-56101
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-28030
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function.

CVE-2025-56092
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 2 PoCs

OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-56086
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-13226
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-8011
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-54918
Windows 10 Version 1507 Windows
8.8
HIGH
EPSS
0.2%
2025 CWE-287 1 PoC

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

CVE-2025-4096
Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-122 1 PoC

Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-57457
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 2 PoCs

An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter.

CVE-2025-3671
WPGYM - Wordpress Gym Management System Web Windows
8.8
HIGH
EPSS
0.2%
2025 CWE-22 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The Local File Inclusion exploit can be chained to i

CVE-2025-9866
Chrome General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)