5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-30220
geoserver General ⚡ nuclei
9.9
CRITICAL
EPSS
13.9%
2025 CWE-611 0 PoCs

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used

CVE-2025-44823
Log Server Web
9.9
CRITICAL
EPSS
0.8%
2025 CWE-497 2 PoCs

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.

CVE-2025-20286
Cisco Identity Services Engine Software Networking Database Cloud
9.9
CRITICAL
EPSS
0.2%
2025 CWE-259 1 PoC

A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multipl

CVE-2025-46157
Software Genérico General
9.9
CRITICAL
EPSS
0.9%
2025 1 PoC

An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form

CVE-2025-70830
Software Genérico Database
9.9
CRITICAL
EPSS
0.0%
2025 2 PoCs

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.

CVE-2025-26892
Celestial Aura General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

CVE-2025-32682
MapSVG General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through <= 8.6.4.

CVE-2025-20051
Mattermost General
9.9
CRITICAL
EPSS
0.3%
2025 CWE-22 1 PoC

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially crafted block in Boards.

CVE-2025-30911
RTMKit General
9.9
CRITICAL
EPSS
1.7%
2025 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.

CVE-2025-32579
Sync Posts General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects Sync Posts: from n/a through <= 1.0.

CVE-2025-46093
LiquidFiles General
9.9
CRITICAL
EPSS
0.2%
2025 CWE-732 1 PoC

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

CVE-2025-12421
Mattermost Windows
9.9
CRITICAL
EPSS
0.1%
2025 CWE-303 1 PoC

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

CVE-2025-49113
🔥 KEV Webmail Web ⚡ nuclei
9.9
CRITICAL
EPSS
90.4%
2025 CWE-502 25 PoCs

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

CVE-2025-54381
BentoML Web Cloud
9.9
CRITICAL
EPSS
0.7%
2025 CWE-918 2 PoCs

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make arbitrary HTTP requests. The vulnerability stems from the multipart form data and JSON request handlers, which automatically download files from user-provided URLs without validating whether those URLs point to internal network addresses, cloud metadata endpoints, or other restricted resources. The documentation explicitl

CVE-2025-27554
ToDesktop General
9.9
CRITICAL
EPSS
0.6%
2025 CWE-94 1 PoC

ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a postinstall script in package.json. No exploitation occurred.

CVE-2025-58443
fogproject Database ⚡ nuclei
9.9
CRITICAL
EPSS
11.0%
2025 CWE-306 2 PoCs

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without credentials. A fix is expected to be released 9/15/2025. To address this vulnerability immediately, upgrade to the latest version of either the dev-branch or working-1.6 branch. This will patch the issue for users concerned about immediate exposure. See the FOG Project documentation for step-by-step upgrade instructions: h

CVE-2025-13032
(Free/Premiium/Ultimeat) Antivirus Windows
9.9
CRITICAL
EPSS
0.0%
2025 CWE-367 1 PoC

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

CVE-2025-69691
Software Genérico Web
9.9
CRITICAL
EPSS
0.0%
2025 1 PoC

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

CVE-2025-2747
🔥 KEV Xperience General ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2025 CWE-288 2 PoCs

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.

CVE-2025-27645
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting HTTP Permission Methods on the Server Side V-2024-005.