5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-0291
Chrome General
8.3
HIGH
EPSS
12.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2025-2783
🔥 KEV Chrome Windows
8.3
HIGH
EPSS
46.9%
2025 2 PoCs

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVE-2025-34066
IP cameras Web Cloud
8.3
HIGH
EPSS
0.2%
2025 CWE-295 2 PoCs

An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.

CVE-2025-54075
mdc Web
8.3
HIGH
EPSS
0.1%
2025 CWE-79 1 PoC

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>` tag rewrites how all subsequent relative URLs are resolved, so an attacker can make the page load scripts, styles, or images from an external, attacker-controlled origin and execute arbitrary JavaScript in the site’s context. Version 0.17.2 contains a fix for the issue.

CVE-2025-60880
Software Genérico Web
8.3
HIGH
EPSS
0.0%
2025 1 PoC

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.

CVE-2025-55903
Software Genérico General
8.3
HIGH
EPSS
0.1%
2025 2 PoCs

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

CVE-2025-64057
Software Genérico General
8.3
HIGH
EPSS
0.1%
2025 1 PoC

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

CVE-2025-36727
Simplehelp General
8.3
HIGH
EPSS
0.1%
2025 CWE-829 1 PoC

Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.

CVE-2025-26529
moodle Web
8.3
HIGH
EPSS
1.0%
2025 CWE-79 1 PoC

Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

CVE-2025-4759
lockfile-lint-api Web
8.3
HIGH
EPSS
0.2%
2025 CWE-179 1 PoC

Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.

CVE-2025-42620
Vulnerability-Lookup Web
8.3
HIGH
EPSS
0.0%
2025 CWE-79 1 PoC

In affected versions, vulnerability-lookup handled user-controlled content in comments and bundles in an unsafe way, which could lead to stored Cross-Site Scripting (XSS). On the backend, the related_vulnerabilities field of bundles accepted arbitrary strings without format validation or proper sanitization. On the frontend, comment and bundle descriptions were converted from Markdown to HTML and then injected directly into the DOM using string templates and innerHTML. This combination allowed an attacker who could create or edit comments or bundles to store crafted HTML/JavaScript

CVE-2025-9624
OpenSearch General
8.3
HIGH
EPSS
0.0%
2025 CWE-674 1 PoC

A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.

CVE-2025-53652
Jenkins Git Parameter Plugin DevOps
8.2
HIGH
EPSS
0.1%
2025 1 PoC

Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.

CVE-2025-65742
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2025 1 PoC

An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.

CVE-2025-3947
C300 PCNT02 General
8.2
HIGH
EPSS
0.4%
2025 CWE-191 1 PoC

The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in improper integer data value checking during subtraction leading to a denial of service. Honeywell recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1. The affected Experion PKS products are C300 PCNT02, C300 PCNT05, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are

CVE-2025-52461
libbiosig General
8.2
HIGH
EPSS
0.1%
2025 CWE-125 2 PoCs

An out-of-bounds read vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-22381
Software Genérico General
8.2
HIGH
EPSS
0.0%
2025 1 PoC

Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.

CVE-2025-57564
Software Genérico Web Database
8.2
HIGH
EPSS
0.1%
2025 1 PoC

CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/insert/elasticsearch/_bulk endpoint. This endpoint accepts bulk log data without requiring authentication or input validation, allowing remote attackers to perform unauthorized log injection. Exploitation may lead to false log entries, log poisoning, alert obfuscation, and potential performance degradation of the observability pipeline. The issue is present in the core CubeAPM platform and is not limited to specific deployment configurations.

CVE-2025-0611
Chrome General
8.2
HIGH
EPSS
0.6%
2025 1 PoC

Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-61536
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2025 1 PoC

FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point to attacker-controlled domains or be delivered via insecure HTTP, enabling token theft, phishing, and account takeover.