299 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-10353
Melis Platform Web ⚡ nuclei
9.3
CRITICAL
EPSS
1.3%
2025 CWE-43 2 PoCs

File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.

CVE-2025-13315
Twonky Server Web Windows ⚡ nuclei
9.3
CRITICAL
EPSS
83.9%
2025 CWE-420 1 PoC

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

CVE-2025-0868
DocsGPT Web ⚡ nuclei
9.3
CRITICAL
EPSS
15.9%
2025 CWE-95 1 PoC

A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from 0.8.1 through 0.12.0.

CVE-2025-34028
🔥 KEV Command Center Innovation Release General ⚡ nuclei
9.3
CRITICAL
EPSS
61.6%
2025 CWE-22 5 PoCs

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.

CVE-2025-32969
xwiki-platform Database ⚡ nuclei
9.3
CRITICAL
EPSS
31.4%
2025 CWE-89 0 PoCs

XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the database backend, including when "Prevent unregistered users from viewing pages, regardless of the page rights" and "Prevent unregistered users from editing pages, regardless of the page rights" options are enabled. Depending on the used database backend, the attacker may be able to not only obtain confidential information

CVE-2025-34299
Monsta FTP General ⚡ nuclei
9.3
CRITICAL
EPSS
69.6%
2025 CWE-434 1 PoC

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

CVE-2025-2776
🔥 KEV SysAid On-Prem General ⚡ nuclei
9.3
CRITICAL
EPSS
62.6%
2025 CWE-611 2 PoCs

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

CVE-2025-54068
🔥 KEV livewire Web ⚡ nuclei
9.2
CRITICAL
EPSS
58.8%
2025 CWE-94 1 PoC

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this

CVE-2025-34026
🔥 KEV Concerto General ⚡ nuclei
9.2
CRITICAL
EPSS
71.1%
2025 CWE-288 1 PoC

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

CVE-2025-49029
Custom Login And Signup Widget General ⚡ nuclei
9.1
CRITICAL
EPSS
0.7%
2025 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0.

CVE-2025-6205
🔥 KEV DELMIA Apriso General ⚡ nuclei
9.1
CRITICAL
EPSS
77.7%
2025 CWE-862 0 PoCs

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

CVE-2025-29927
next.js General ⚡ nuclei
9.1
CRITICAL
EPSS
92.1%
2025 CWE-285 98 PoCs

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

CVE-2025-54236
🔥 KEV Adobe Commerce General ⚡ nuclei
9.1
CRITICAL
EPSS
64.8%
2025 CWE-20 1 PoC

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

CVE-2025-48828
vBulletin Web ⚡ nuclei
9.0
CRITICAL
EPSS
73.7%
2025 CWE-424 3 PoCs

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.

CVE-2025-23061
Mongoose General ⚡ nuclei
9.0
CRITICAL
EPSS
55.3%
2025 CWE-94 0 PoCs

Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.

CVE-2025-48703
🔥 KEV CentOS Web Panel General ⚡ nuclei
9.0
CRITICAL
EPSS
72.6%
2025 CWE-78 3 PoCs

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CVE-2025-30406
🔥 KEV CentreStack General ⚡ nuclei
9.0
CRITICAL
EPSS
83.4%
2025 CWE-321 6 PoCs

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.

CVE-2025-0282
🔥 KEV Connect Secure General ⚡ nuclei
9.0
CRITICAL
EPSS
94.1%
2025 CWE-121 11 PoCs

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2025-5086
🔥 KEV DELMIA Apriso General ⚡ nuclei
9.0
CRITICAL
EPSS
42.1%
2025 CWE-502 1 PoC

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

CVE-2025-24514
ingress-nginx DevOps Web ⚡ nuclei
8.8
HIGH
EPSS
51.6%
2025 CWE-20 2 PoCs

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)