17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-14892
Prime Listing Manager Web Windows
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.

CVE-2025-26817
Software Genérico General
9.8
CRITICAL
EPSS
2.7%
2025 1 PoC

Netwrix Password Secure 9.2.0.32454 allows OS command injection.

CVE-2025-30113
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and 9092. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.

CVE-2025-1661
HUSKY – Products Filter Professional for WooCommerce Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2025 CWE-22 3 PoCs

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2025-9083
Ninja Forms Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2025-31033
Buddypress Humanity Web
9.8
CRITICAL
EPSS
0.2%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.

CVE-2025-10640
WorkExaminer Professional General
9.8
CRITICAL
EPSS
0.5%
2025 CWE-602 2 PoCs

An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side authentication checks to bypass the login prompt in the WorkExaminer Professional console to gain administrative access to the WorkExaminer server and therefore all sensitive monitoring data. This includes monitored screenshots and keystrokes of all users. The WorkExaminer Professional console is used for administrative access to the server. Before access to the console is granted administrators must login. Internally, a custom protocol is used to call a respective stored proce

CVE-2025-22953
Software Genérico Database
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads into the filter parameter, enabling the unauthorized execution of arbitrary SQL commands on the backend database. If certain features (like xp_cmdshell) are enabled, this may lead to remote code execution.

CVE-2025-49825
teleport General ⚡ nuclei
9.8
CRITICAL
EPSS
17.8%
2025 CWE-863 0 PoCs

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

CVE-2025-44897
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.

CVE-2025-30457
macOS General
9.8
CRITICAL
EPSS
0.9%
2025 1 PoC

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to create symlinks to protected regions of the disk.

CVE-2025-8356
FreeFlow Core General
9.8
CRITICAL
EPSS
1.8%
2025 CWE-22 1 PoC

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.

CVE-2025-50594
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management System EMR 3.2 allowing attackers to reset any account password.

CVE-2025-28038
Software Genérico General
9.8
CRITICAL
EPSS
8.2%
2025 1 PoC

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

CVE-2025-28242
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
11.5%
2025 1 PoC

Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

CVE-2025-11148
check-branches General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-78 1 PoC

All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted with locally, or via CI, to confirm no conflicts exist in git branches. However, the library follows these conventions which can be abused: 1. It trusts branch names as they are (plain text) 2. It spawns git commands by concatenating user input Since a branch name is potentially a user input - as users can create branches remotely via pull requests, or simply due to privileged access to a repository - it can effectively be abused to run any command.

CVE-2025-1009
Firefox General
9.8
CRITICAL
EPSS
0.8%
2025 1 PoC

An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

CVE-2025-5394
Alone – Charity Multipurpose Non-profit WordPress Theme Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
17.5%
2025 CWE-862 4 PoCs

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. CVE-2025-54019 is likely a duplicate of this.

CVE-2025-24246
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

CVE-2025-27646
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Account Exposure V-2024-001.