299 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-5394
Alone – Charity Multipurpose Non-profit WordPress Theme Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
17.5%
2025 CWE-862 4 PoCs

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. CVE-2025-54019 is likely a duplicate of this.

CVE-2025-3605
Login, Registration and Lost Password Blocks Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
12.7%
2025 CWE-639 2 PoCs

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via the flr_blocks_user_settings_handle_ajax_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

CVE-2025-32814
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
32.1%
2025 0 PoCs

An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

CVE-2025-53770
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.5%
2025 CWE-502 46 PoCs

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

CVE-2025-1302
jsonpath-plus Web ⚡ nuclei
9.8
CRITICAL
EPSS
89.9%
2025 CWE-94 4 PoCs

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).

CVE-2025-22952
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
24.9%
2025 0 PoCs

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.

CVE-2025-28242
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
11.5%
2025 1 PoC

Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

CVE-2025-41646
Revolution Pi webstatus General ⚡ nuclei
9.8
CRITICAL
EPSS
33.8%
2025 CWE-704 3 PoCs

An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device

CVE-2025-58434
Flowise Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
21.0%
2025 CWE-306 0 PoCs

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai.com`) and self-hosted/local Flowise deployments that expose the same API. Commit 9e178d68873eb876073

CVE-2025-49533
Adobe Experience Manager (MS) General ⚡ nuclei
9.8
CRITICAL
EPSS
76.4%
2025 CWE-502 0 PoCs

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

CVE-2025-2747
🔥 KEV Xperience General ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2025 CWE-288 2 PoCs

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.

CVE-2025-56266
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
7.1%
2025 0 PoCs

A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.

CVE-2025-6934
Opal Estate Pro – Property Management and Submission Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
28.0%
2025 CWE-269 9 PoCs

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.

CVE-2025-5947
Service Finder Bookings Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
43.8%
2025 CWE-639 4 PoCs

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it possible for unauthenticated attackers to login as any user including admins.

CVE-2025-6058
WPBookit Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
26.7%
2025 CWE-434 4 PoCs

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-4632
🔥 KEV MagicINFO 9 Server General ⚡ nuclei
9.8
CRITICAL
EPSS
49.2%
2025 CWE-22 1 PoC

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

CVE-2025-4322
Motors - Car Dealer, Rental & Listing WordPress theme Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
43.9%
2025 CWE-620 3 PoCs

The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account.

CVE-2025-4334
Simple User Registration Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
34.1%
2025 CWE-269 3 PoCs

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.

CVE-2025-61882
🔥 KEV Oracle Concurrent Processing Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2025 11 PoCs

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2025-8868
Chef Automate Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.3%
2025 CWE-200 0 PoCs

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.