824 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-26206
Software Genérico General
9.0
CRITICAL
EPSS
0.4%
2025 1 PoC

Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component

CVE-2025-8264
z-push/z-push-dev Web Database Windows
9.0
CRITICAL
EPSS
0.1%
2025 CWE-89 1 PoC

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. This allows the attacker to access and potentially modify or delete sensitive data from a linked third-party database. **Note:** This vulnerability affects Z-Push installations that utilize the IMAP backend and have the IMAP_FROM_SQL_QUERY option configured. Mitigation Change configuration to use the default or LDAP in backend/imap/config.php php defi

CVE-2025-22144
Nameless Web
9.0
CRITICAL
EPSS
0.4%
2025 CWE-610 1 PoC

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually validated by a user with admincp.core.emails or admincp.users.edit permissions then the reset_code will no longer be NULL but empty. An attacker can request http://localhost/nameless/index.php?route=/forgot_password/&c= and reset the password. As a result an attacker may compromi

CVE-2025-54309
🔥 KEV CrushFTP Web
9.0
CRITICAL
EPSS
77.8%
2025 CWE-420 10 PoCs

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.