5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-0749
Homey Web Windows
8.1
HIGH
EPSS
0.0%
2025 CWE-288 1 PoC

The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user.

CVE-2025-10854
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 CWE-61 1 PoC

The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is intended to prevent path traversal vulnerabilities by ensuring safe filenames, it does not account for symbolic links within the tar file. An attacker is able to write a file anywhere in the filesystem when txtai is used to load untrusted embedding indices

CVE-2025-24180
Safari General
8.1
HIGH
EPSS
0.2%
2025 2 PoCs

The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.

CVE-2025-30712
Oracle VM VirtualBox Database
8.1
HIGH
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox access

CVE-2025-25950
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 1 PoC

Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

CVE-2025-65128
Software Genérico Web Networking
8.1
HIGH
EPSS
0.1%
2025 1 PoC

A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected by the invoked function, an attacker can change configuration data, including SSID, Wi-Fi credentials, and administrative passwords, without authentication or an existing session.

CVE-2025-46414
EG4 12kPV Web
8.1
HIGH
EPSS
0.1%
2025 CWE-307 1 PoC

The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using brute-force methods if they possess a valid device serial number. The API provides clear feedback when the correct PIN is entered. This vulnerability was patched in a server-side update on April 6, 2025.

CVE-2025-64729
Process Optimization General
8.1
HIGH
EPSS
0.0%
2025 CWE-862 1 PoC

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.

CVE-2025-3102
OttoKit: All-in-One Automation Platform Web Windows ⚡ nuclei
8.1
HIGH
EPSS
87.8%
2025 CWE-697 10 PoCs

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVE-2025-52690
OmniAccess Stellar Products General
8.1
HIGH
EPSS
0.1%
2025 CWE-77 1 PoC

Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.

CVE-2025-24035
Windows 10 Version 1507 Windows
8.1
HIGH
EPSS
0.1%
2025 CWE-591 1 PoC

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVE-2025-55998
Software Genérico Web
8.1
HIGH
EPSS
0.0%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter

CVE-2025-1932
Firefox General
8.1
HIGH
EPSS
0.2%
2025 1 PoC

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-60378
Software Genérico General
8.1
HIGH
EPSS
0.2%
2025 1 PoC

Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.

CVE-2025-1290
ChromeOS General
8.1
HIGH
EPSS
0.3%
2025 1 PoC

A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution.

CVE-2025-27480
Windows Server 2012 Windows
8.1
HIGH
EPSS
0.8%
2025 CWE-416 2 PoCs

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

CVE-2025-3515
Drag and Drop Multiple File Upload for Contact Form 7 Web Windows ⚡ nuclei
8.1
HIGH
EPSS
4.6%
2025 CWE-434 6 PoCs

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other dangerous file types on the affected site's server, which may make remote code execution possible on the servers that are configured to handle .phar files as executable PHP scripts, particularly in default Apache+mod_php configurations where the file extension is not strictly vali

CVE-2025-58075
Mattermost General
8.1
HIGH
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState

CVE-2025-48416
cPH2 / cPP2 charging stations Networking
8.1
HIGH
EPSS
0.3%
2025 CWE-912 2 PoCs

An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image for the "root" user. However, in the default SSH configuration the "PermitRootLogin" is disabled, preventing the root user from logging in via SSH. This configuration can be bypassed/changed by an attacker through multiple paths though.