5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-41675
mbNET.mini Cloud
7.2
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.

CVE-2025-22210
Hikashop component for Joomla Web Database
7.2
HIGH
EPSS
0.1%
2025 CWE-89 1 PoC

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.

CVE-2025-4428
🔥 KEV Endpoint Manager Mobile Web
7.2
HIGH
EPSS
26.2%
2025 CWE-94 3 PoCs

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

CVE-2025-3944
Niagara Framework General
7.2
HIGH
EPSS
0.3%
2025 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-32370
Xperience Web
7.2
HIGH
EPSS
0.3%
2025 CWE-912 2 PoCs

Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions. NOTE: this is a separate issue not necessarily related to SVG or XSS.

CVE-2025-55988
Software Genérico Web
7.2
HIGH
EPSS
0.1%
2025 1 PoC

An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path.

CVE-2025-41673
mbNET.mini General
7.2
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command.

CVE-2025-13307
Ocean Modal Window Web Windows
7.2
HIGH
EPSS
0.4%
2025 1 PoC

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

CVE-2025-14273
Mattermost General
7.2
HIGH
EPSS
0.1%
2025 CWE-303 1 PoC

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST requests to the Jira server via crafted plugin payloads that spoof the user ID and inject arbitrary issue key paths. Mattermost Advisory ID: MMSA-2025-00555

CVE-2025-45753
Software Genérico Web
7.2
HIGH
EPSS
0.4%
2025 1 PoC

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

CVE-2025-0514
LibreOffice Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-20 1 PoC

Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5.

CVE-2025-4687
RMS General
7.2
HIGH
EPSS
0.2%
2025 1 PoC

In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge. The victims account and their company can then be managed by the attacker.This issue affects RMS: before 5.7.

CVE-2025-44004
Mattermost Confluence Plugin Web
7.2
HIGH
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.

CVE-2025-50891
server-side backend for Site Tracking General
7.2
HIGH
EPSS
0.1%
2025 CWE-79 1 PoC

The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1).

CVE-2025-6624
snyk DevOps
7.2
HIGH
EPSS
0.1%
2025 CWE-532 1 PoC

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI in DEBUG or DEBUG/TRACE mode. The issue affects the following Snyk commands: 1. When snyk container test or snyk container monitor commands are run against a container registry, with debug mode enabled, the container registry credentials may be written into the local Snyk CLI debug log. This only happens with credentia

CVE-2025-28403
Software Genérico General
7.2
HIGH
EPSS
0.8%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

CVE-2025-7050
Use-your-Drive | Google Drive plugin for WordPress Web Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-79 1 PoC

The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability can be exploited by the lowest authentication level permitted to upload files, including unauthenticated users, once a file upload shortcode is published on a publicly accessi

CVE-2025-63220
Software Genérico General
7.2
HIGH
EPSS
0.2%
2025 1 PoC

The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.

CVE-2025-0924
WP Activity Log Web Windows
7.2
HIGH
EPSS
8.5%
2025 CWE-79 1 PoC

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-12973
S2B AI Assistant – ChatBot, AI Agents, ChatGPT API, Image Generator Web Windows
7.2
HIGH
EPSS
0.1%
2025 CWE-434 2 PoCs

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.