5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-52689
OmniAccess Stellar Products General
9.8
CRITICAL
EPSS
0.8%
2025 CWE-384 2 PoCs

Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the access point.

CVE-2025-43951
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.

CVE-2025-63206
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.

CVE-2025-66944
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint

CVE-2025-10127
Security Gateway General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-640 1 PoC

Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.

CVE-2025-56266
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
7.1%
2025 0 PoCs

A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.

CVE-2025-5305
Password Reset with Code for WordPress REST API Web Windows
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.

CVE-2025-47277
vllm General
9.8
CRITICAL
EPSS
0.9%
2025 CWE-502 1 PoC

vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the `PyNcclPipe` KV cache transfer integration with the V0 engine. No other configurations are affected. vLLM supports the use of the `PyNcclPipe` class to establish a peer-to-peer communication domain for data transmission between distributed nodes. The GPU-side KV-Cache transmission is implemented through the `PyNcclCommunicator` class, while CPU-side control message passing is handled via the `send_obj` and `recv_obj` methods on the CPU si

CVE-2025-69258
Trend Micro Apex Central General
9.8
CRITICAL
EPSS
0.6%
2025 CWE-290 1 PoC

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

CVE-2025-8868
Chef Automate Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.3%
2025 CWE-200 0 PoCs

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

CVE-2025-54486
libbiosig General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability manifests on line 8824 of biosig.c on the current master branch (35a819fa), when the Tag is 11: else if (tag==11) //0x0B { // Fs if (len>6) fprintf(stderr,"Warning MFER tag11 incorrect length %i>6\n",len);

CVE-2025-27643
Software Genérico Web Cloud
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Hardcoded AWS API Key V-2024-006.

CVE-2025-48005
libbiosig General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted RHS2000 file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-0674
Signum DVB-S/S2 IRD General ⚡ nuclei
9.8
CRITICAL
EPSS
15.8%
2025 CWE-288 0 PoCs

Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user's password within the system. This grants them unauthorized administrative access to protected areas of the application, compromising the device's system security.

CVE-2025-25256
FortiSIEM Networking
9.8
CRITICAL
EPSS
46.6%
2025 CWE-78 4 PoCs

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 through 7.1.7, 7.0.0 through 7.0.3 and before 6.7.9 allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.

CVE-2025-10542
iMonitor EAM General
9.8
CRITICAL
EPSS
0.2%
2025 CWE-1392 3 PoCs

iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This enables reading highly sensitive telemetry (including keylogger output) and issuing arbitrary actions to all connected clients.

CVE-2025-59287
🔥 KEV Windows Server 2012 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
72.2%
2025 CWE-502 4 PoCs

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CVE-2025-22939
Software Genérico General
9.8
CRITICAL
EPSS
6.2%
2025 2 PoCs

A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.

CVE-2025-45947
Software Genérico Web
9.8
CRITICAL
EPSS
1.3%
2025 1 PoC

An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component

CVE-2025-65236
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.