5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-12055
MIP 2 Windows ⚡ nuclei
7.5
HIGH
EPSS
22.3%
2025 CWE-22 2 PoCs

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36 with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system. The "Filename" parameter of the public $SCHEMAS$ ressource is vulnerable and can be exploited easily.

CVE-2025-51005
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file is processed, the program incorrectly handles memory in the checksum calculation logic at do_checksum_math_liveplay in tcpliveplay.c, leading to a possible denial of service.

CVE-2025-5287
Likes and Dislikes Plugin Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
10.0%
2025 CWE-89 4 PoCs

The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-70147
Software Genérico Web
7.5
HIGH
EPSS
0.3%
2025 1 PoC

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.

CVE-2025-65518
Software Genérico Web
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.

CVE-2025-62771
M6a Web
7.5
HIGH
EPSS
0.0%
2025 CWE-352 1 PoC

Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.

CVE-2025-11678
libwebsocket General
7.5
HIGH
EPSS
0.0%
2025 CWE-121 1 PoC

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.

CVE-2025-25685
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a samba share.

CVE-2025-27580
BRICS General
7.5
HIGH
EPSS
0.6%
2025 CWE-335 1 PoC

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.

CVE-2025-1323
WP-Recall – Registration, Profile, Commerce & More Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
27.3%
2025 CWE-89 1 PoC

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-66960
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 1 PoC

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

CVE-2025-1710
Endress+Hauser MEAC300-FNADE4 General
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-10497
GitLab DevOps
7.5
HIGH
EPSS
0.1%
2025 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

CVE-2025-63800
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.

CVE-2025-14542
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 CWE-501 1 PoC

The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endpoint. While a provider may initially serve a benign manual (e.g., one defining an HTTP tool call), earning the clients’ trust, a malicious provider can later change the manual to exploit the client.

CVE-2025-25709
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the addUser and updateUser endpoints

CVE-2025-58410
Graphics DDK General
7.5
HIGH
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections for the buffer resource.

CVE-2025-66905
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.

CVE-2025-24970
netty General
7.5
HIGH
EPSS
1.0%
2025 CWE-20 2 PoCs

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.

CVE-2025-66744
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
6.0%
2025 0 PoCs

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system