299 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-28242
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
11.5%
2025 1 PoC

Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

CVE-2025-61882
🔥 KEV Oracle Concurrent Processing Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2025 11 PoCs

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2025-58434
Flowise Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
21.0%
2025 CWE-306 0 PoCs

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai.com`) and self-hosted/local Flowise deployments that expose the same API. Commit 9e178d68873eb876073

CVE-2025-6058
WPBookit Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
26.7%
2025 CWE-434 4 PoCs

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-53770
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.5%
2025 CWE-502 46 PoCs

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

CVE-2025-54123
hoverfly Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
58.1%
2025 CWE-20 0 PoCs

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injection vulnerability at `/api/v2/hoverfly/middleware` endpoint due to insufficient validation and sanitization in user input. The vulnerability exists in the middleware management API endpoint `/api/v2/hoverfly/middleware`. This issue is born due to combination of three code level flaws: Insufficient Input Validation in middleware.go line 94-96; Unsafe Command Execution in local_middleware.go line 14-19; and Immediate Execution During Testing in hov

CVE-2025-1661
HUSKY – Products Filter Professional for WooCommerce Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2025 CWE-22 3 PoCs

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2025-4632
🔥 KEV MagicINFO 9 Server General ⚡ nuclei
9.8
CRITICAL
EPSS
49.2%
2025 CWE-22 1 PoC

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

CVE-2025-31161
🔥 KEV CrushFTP Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
86.2%
2025 CWE-305 20 PoCs

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible with S3) authorization method of the HTTP component of the FTP server. The server first verifies the existence of the user by performing a call to login_user_pass() with no password requirement. This will authenticate the session through the HMAC verification process and up until the server checks f

CVE-2025-44148
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
14.5%
2025 1 PoC

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

CVE-2025-8868
Chef Automate Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.3%
2025 CWE-200 0 PoCs

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

CVE-2025-49825
teleport General ⚡ nuclei
9.8
CRITICAL
EPSS
17.8%
2025 CWE-863 0 PoCs

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

CVE-2025-44136
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
13.0%
2025 1 PoC

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

CVE-2025-3248
🔥 KEV langflow Web ⚡ nuclei
9.8
CRITICAL
EPSS
91.8%
2025 CWE-306 22 PoCs

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

CVE-2025-25570
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
20.6%
2025 0 PoCs

Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.

CVE-2025-1562
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
19.5%
2025 CWE-862 1 PoC

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_or_activate_addon_plugins() function and a weak nonce hash in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated attackers to install arbitrary plugins on the site that can be leveraged to further infect a vulnerable site.

CVE-2025-56819
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
11.8%
2025 1 PoC

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

CVE-2025-2746
🔥 KEV Xperience General ⚡ nuclei
9.8
CRITICAL
EPSS
89.7%
2025 CWE-288 2 PoCs

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

CVE-2025-1302
jsonpath-plus Web ⚡ nuclei
9.8
CRITICAL
EPSS
89.9%
2025 CWE-94 4 PoCs

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).

CVE-2025-3605
Login, Registration and Lost Password Blocks Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
12.7%
2025 CWE-639 2 PoCs

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via the flr_blocks_user_settings_handle_ajax_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.