17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-8570
BeyondCart Connector Web Windows
9.8
CRITICAL
EPSS
0.1%
2025 CWE-798 1 PoC

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

CVE-2025-66439
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the from_posting_date parameter, which is directly interpolated into the query without proper sanitization or parameter binding.

CVE-2025-56218
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

CVE-2025-70457
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.

CVE-2025-28402
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

CVE-2025-25595
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a brute force attack.

CVE-2025-6934
Opal Estate Pro – Property Management and Submission Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
28.0%
2025 CWE-269 9 PoCs

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.

CVE-2025-58434
Flowise Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
21.0%
2025 CWE-306 0 PoCs

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai.com`) and self-hosted/local Flowise deployments that expose the same API. Commit 9e178d68873eb876073

CVE-2025-66044
libbiosig General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-121 1 PoC

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 64

CVE-2025-24238
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.3%
2025 3 PoCs

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to gain elevated privileges.

CVE-2025-54482
libbiosig General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability manifests on line 8751 of biosig.c on the current master branch (35a819fa), when the Tag is 4: else if (tag==4) { // SPR if (len>4) fprintf(stderr,"Warning MFER tag4 incorrect length %i>4\n",len); curPos += ifread(buf,1,len,hdr);

CVE-2025-24237
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.7%
2025 3 PoCs

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination.

CVE-2025-24260
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker in a privileged position may be able to perform a denial-of-service.

CVE-2025-44893
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 2 PoCs

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.

CVE-2025-44022
Software Genérico Web
9.8
CRITICAL
EPSS
4.5%
2025 1 PoC

An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.

CVE-2025-22941
Software Genérico General
9.8
CRITICAL
EPSS
3.8%
2025 2 PoCs

A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.

CVE-2025-5058
eMagicOne Store Manager for WooCommerce Web Windows
9.8
CRITICAL
EPSS
2.5%
2025 CWE-434 3 PoCs

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This is only exploitable by unauthenticated attackers in default configurations where the the default password is left as 1:1, or where the attacker gains access to the credentials.

CVE-2025-53118
Unified PAM General ⚡ nuclei
9.8
CRITICAL
EPSS
34.6%
2025 CWE-306 0 PoCs

An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.

CVE-2025-65741
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of this library in the context of the Sublime Text application.

CVE-2025-4322
Motors - Car Dealer, Rental & Listing WordPress theme Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
43.9%
2025 CWE-620 3 PoCs

The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account.