17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-6715
LatePoint Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2025-24118
iPadOS General
9.8
CRITICAL
EPSS
27.0%
2025 2 PoCs

The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or write kernel memory.

CVE-2025-24266
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

CVE-2025-54321
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.

CVE-2025-29411
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2025-5947
Service Finder Bookings Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
43.8%
2025 CWE-639 4 PoCs

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it possible for unauthenticated attackers to login as any user including admins.

CVE-2025-68615
net-snmp General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-119 2 PoCs

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.

CVE-2025-45813
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

CVE-2025-8043
Firefox General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.

CVE-2025-29659
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2025 1 PoC

Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.

CVE-2025-2266
Checkout Mestres do WP for WooCommerce Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 CWE-862 1 PoC

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVE-2025-55835
Software Genérico Web
9.8
CRITICAL
EPSS
1.3%
2025 1 PoC

File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.

CVE-2025-27657
Software Genérico General
9.8
CRITICAL
EPSS
1.8%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.

CVE-2025-46070
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

CVE-2025-59359
Software Genérico General
9.8
CRITICAL
EPSS
1.5%
2025 CWE-78 1 PoC

The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.

CVE-2025-44884
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.

CVE-2025-22937
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2025 2 PoCs

An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.

CVE-2025-63958
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update parameters. An unauthenticated attacker can retrieve this information by accessing the endpoint directly, potentially leading to full system compromise. The vulnerability is due to missing access controls on a privileged administrative function.

CVE-2025-10915
Dreamer Blog Web Windows
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check.

CVE-2025-27677
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged File Interaction V-2022-002.