2326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-53691
Experience Manager (XM) General
8.8
HIGH
EPSS
4.2%
2025 CWE-502 5 PoCs

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.

CVE-2025-31722
Jenkins Templating Engine Plugin DevOps
8.8
HIGH
EPSS
1.1%
2025 1 PoC

In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.

CVE-2025-29509
Software Genérico Web
8.8
HIGH
EPSS
0.7%
2025 1 PoC

Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external website in the app and the exposure of electronAPI, with a lack of filtering of URL when calling shell.openExternal().

CVE-2025-10533
Firefox General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVE-2025-32451
Foxit Reader Web
8.8
HIGH
EPSS
0.2%
2025 CWE-824 2 PoCs

A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2025-56096
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the restart_modules in file /usr/lib/lua/luci/controller/admin/common.lua.

CVE-2025-26326
Software Genérico General
8.8
HIGH
EPSS
3.3%
2025 1 PoC

A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain total control of the remote system by guessing a weak password. The problem occurs because these add-ons accept any password entered by the user and do not have an additional authentication or computer verification mechanism. Tests indicate that more than 1,000 systems use easy-to-guess passwords, many with less than 4 to 6 characters, including common sequences. This allows brute force attacks or trial-and-error attempts by mal

CVE-2025-0593
SICK Lector8xx General
8.8
HIGH
EPSS
0.1%
2025 CWE-77 1 PoC

The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the device.

CVE-2025-20946
Samsung Mobile Devices General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Improper handling of exceptional conditions in pairing specific bluetooth devices in Galaxy Watch Bluetooth pairing prior to SMR Apr-2025 Release 1 allows local attackers to pair with specific bluetooth devices without user interaction.

CVE-2025-43953
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or traceroute field on the TCP/IP screen.

CVE-2025-47713
Apache CloudStack Web Cloud
8.8
HIGH
EPSS
0.2%
2025 CWE-269 1 PoC

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricted and allows the attacker to assume control over higher-privileged user-accounts. A malicious Domain Admin attacker can impersonate an Admin user-account and gain access to sensitive APIs and resources that could result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of infrastru

CVE-2025-10200
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVE-2025-51865
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

CVE-2025-28237
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.

CVE-2025-24514
ingress-nginx DevOps Web ⚡ nuclei
8.8
HIGH
EPSS
51.6%
2025 CWE-20 2 PoCs

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVE-2025-55204
muffon General
8.8
HIGH
EPSS
0.5%
2025 CWE-94 1 PoC

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on any website they control. When a victim visits the site or clicks the link, the browser triggers Muffon’s custom URL handler, causing the application to launch and process the URL. This leads to RCE on the victim's machine without further interaction. Version 2.3.0 patches the issue.

CVE-2025-13228
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-50944
Software Genérico General
8.8
HIGH
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation.

CVE-2025-51482
Software Genérico Web Networking ⚡ nuclei
8.8
HIGH
EPSS
5.8%
2025 2 PoCs

Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions.

CVE-2025-5280
Chrome General
8.8
HIGH
EPSS
0.6%
2025 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)