5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-2691
nossrf General
8.2
HIGH
EPSS
0.0%
2025 CWE-918 1 PoC

Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.

CVE-2025-56551
Software Genérico General
8.2
HIGH
EPSS
0.1%
2025 1 PoC

An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.

CVE-2025-14523
Red Hat Enterprise Linux 10 Web
8.2
HIGH
EPSS
0.0%
2025 CWE-444 1 PoC

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.

CVE-2025-1533
Armoury Crate General
8.2
HIGH
EPSS
0.1%
2025 CWE-121 1 PoC

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

CVE-2025-61553
Software Genérico General
8.2
HIGH
EPSS
0.0%
2025 1 PoC

An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration space access. Given it's a heap overflow in a privileged hypervisor context, exploitation may enable arbitrary code execution or guest-to-host privilege escalation.

CVE-2025-63298
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2025 1 PoC

A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request, enabling the deletion of arbitrary files on the web server or underlying operating system.

CVE-2025-29093
Software Genérico General
8.2
HIGH
EPSS
1.0%
2025 2 PoCs

File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component.

CVE-2025-44177
Software Genérico General ⚡ nuclei
8.2
HIGH
EPSS
9.3%
2025 0 PoCs

A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An unauthenticated attacker can remotely read arbitrary files on the underlying OS using encoded traversal sequences.

CVE-2025-52461
libbiosig General
8.2
HIGH
EPSS
0.1%
2025 CWE-125 2 PoCs

An out-of-bounds read vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-61536
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2025 1 PoC

FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point to attacker-controlled domains or be delivered via insecure HTTP, enabling token theft, phishing, and account takeover.

CVE-2025-34208
Print Virtual Appliance Host Web
8.2
HIGH
EPSS
0.1%
2025 CWE-327 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords using unsalted SHA-512 hashes with a fall-back to unsalted SHA-1. The hashing is performed via PHP's `hash()` function in multiple files (server_write_requests_users.php, update_database.php, legacy/Login.php, tests/Unit/Api/IdpControllerTest.php). No per-user salt is used and the fast hash algorithms are unsuitable for password storage. An attacker who obtains the password database can recover cleartext passwords via offline dictionary or rainbow table attacks. The vulnerable

CVE-2025-43865
react-router Networking
8.2
HIGH
EPSS
0.3%
2025 CWE-345 1 PoC

React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.

CVE-2025-22381
Software Genérico General
8.2
HIGH
EPSS
0.0%
2025 1 PoC

Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.

CVE-2025-53027
Oracle VM VirtualBox Database
8.2
HIGH
EPSS
0.0%
2025 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability imp

CVE-2025-46067
Software Genérico General
8.2
HIGH
EPSS
0.1%
2025 1 PoC

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file

CVE-2025-65001
fbiosdrv.sys General
8.2
HIGH
EPSS
0.0%
2025 CWE-787 1 PoC

Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and availability.

CVE-2025-2594
User Registration & Membership Web Windows
8.1
HIGH
EPSS
7.4%
2025 2 PoCs

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

CVE-2025-2563
User Registration & Membership Web Windows ⚡ nuclei
8.1
HIGH
EPSS
87.9%
2025 2 PoCs

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges

CVE-2025-1932
Firefox General
8.1
HIGH
EPSS
0.2%
2025 1 PoC

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-60915
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 1 PoC

An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted request.