5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-56089
Software Genérico General
8.8
HIGH
EPSS
0.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVE-2025-46109
Software Genérico Web Database
8.8
HIGH
EPSS
0.4%
2025 1 PoC

SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request

CVE-2025-2135
Chrome General
8.8
HIGH
EPSS
2.6%
2025 CWE-843 3 PoCs

Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-1568
ChromeOS General
8.8
HIGH
EPSS
0.8%
2025 1 PoC

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.

CVE-2025-13228
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-56120
Software Genérico General
8.8
HIGH
EPSS
0.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

CVE-2025-21042
🔥 KEV Samsung Mobile Devices General
8.8
HIGH
EPSS
3.3%
2025 1 PoC

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

CVE-2025-28237
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.

CVE-2025-51865
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

CVE-2025-60311
Software Genérico Web Database
8.8
HIGH
EPSS
0.0%
2025 1 PoC

ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page

CVE-2025-56107
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config.lua.

CVE-2025-56084
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVE-2025-9132
Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-21064
Smart Switch General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

CVE-2025-0995
Chrome General
8.8
HIGH
EPSS
0.3%
2025 CWE-416 1 PoC

Use after free in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-47713
Apache CloudStack Web Cloud
8.8
HIGH
EPSS
0.2%
2025 CWE-269 1 PoC

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricted and allows the attacker to assume control over higher-privileged user-accounts. A malicious Domain Admin attacker can impersonate an Admin user-account and gain access to sensitive APIs and resources that could result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of infrastru

CVE-2025-45081
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 1 PoC

Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.

CVE-2025-21293
Windows 10 Version 1507 Windows
8.8
HIGH
EPSS
75.8%
2025 CWE-284 1 PoC

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2025-1232
Site Reviews Web Windows ⚡ nuclei
8.8
HIGH
EPSS
20.9%
2025 1 PoC

The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks

CVE-2025-56079
Software Genérico General
8.8
HIGH
EPSS
0.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1.00/V2.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.