5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-1232
Site Reviews Web Windows ⚡ nuclei
8.8
HIGH
EPSS
20.9%
2025 1 PoC

The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks

CVE-2025-8010
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-56129
Software Genérico General
8.8
HIGH
EPSS
1.4%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnosis in file /usr/lib/lua/luci/controller/admin/diagnosis.lua.

CVE-2025-54769
LPAR2RRD General
8.8
HIGH
EPSS
6.1%
2025 CWE-24 2 PoCs

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

CVE-2025-54106
Windows Server 2012 R2 Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-190 1 PoC

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-31129
jooby General
8.8
HIGH
EPSS
0.5%
2025 CWE-502 1 PoC

Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 (3.x).

CVE-2025-21371
Windows 10 Version 1507 Windows
8.8
HIGH
EPSS
0.2%
2025 CWE-122 2 PoCs

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-28237
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.

CVE-2025-53778
Windows 10 Version 1507 Windows
8.8
HIGH
EPSS
1.0%
2025 CWE-287 3 PoCs

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

CVE-2025-53772
Web Deploy 4.0 General
8.8
HIGH
EPSS
11.1%
2025 CWE-502 3 PoCs

Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

CVE-2025-56093
Software Genérico General
8.8
HIGH
EPSS
0.5%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless.lua.

CVE-2025-51865
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

CVE-2025-63406
Software Genérico Web
8.8
HIGH
EPSS
0.6%
2025 2 PoCs

An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php

CVE-2025-52930
SAIL Image Decoding Library General
8.8
HIGH
EPSS
0.4%
2025 CWE-680 2 PoCs

A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially crafted .bmp file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

CVE-2025-47713
Apache CloudStack Web Cloud
8.8
HIGH
EPSS
0.2%
2025 CWE-269 1 PoC

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricted and allows the attacker to assume control over higher-privileged user-accounts. A malicious Domain Admin attacker can impersonate an Admin user-account and gain access to sensitive APIs and resources that could result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of infrastru

CVE-2025-24514
ingress-nginx DevOps Web ⚡ nuclei
8.8
HIGH
EPSS
51.6%
2025 CWE-20 2 PoCs

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVE-2025-29509
Software Genérico Web
8.8
HIGH
EPSS
0.7%
2025 1 PoC

Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external website in the app and the exposure of electronAPI, with a lack of filtering of URL when calling shell.openExternal().

CVE-2025-56079
Software Genérico General
8.8
HIGH
EPSS
0.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1.00/V2.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-65817
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.

CVE-2025-3620
Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-416 1 PoC

Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)