5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-60787
Software Genérico General
7.2
HIGH
EPSS
65.3%
2025 1 PoC

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

CVE-2025-4190
CSV Mass Importer Web Windows
7.2
HIGH
EPSS
0.2%
2025 3 PoCs

The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2025-61482
Software Genérico General
7.2
HIGH
EPSS
0.0%
2025 1 PoC

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of valid one-time passwords, and bypassing authentication for enrolled accounts.

CVE-2025-32813
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
11.2%
2025 0 PoCs

An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

CVE-2025-63215
Software Genérico General
7.2
HIGH
EPSS
0.2%
2025 1 PoC

The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.

CVE-2025-63227
Software Genérico Web
7.2
HIGH
EPSS
0.1%
2025 1 PoC

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This allows the attacker to execute arbitrary commands on the server, potentially leading to full system compromise.

CVE-2025-60500
Software Genérico Web
7.2
HIGH
EPSS
0.2%
2025 1 PoC

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

CVE-2025-63417
Software Genérico Web
7.2
HIGH
EPSS
0.1%
2025 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated attackers to inject arbitrary web scripts or HTML via the chat message input field. This malicious content is stored and then executed in the context of other users' browsers when they view the malicious message, potentially leading to session hijacking, account takeover, or other client-side attacks.

CVE-2025-1080
LibreOffice Windows
7.2
HIGH
EPSS
0.1%
2025 CWE-20 1 PoC

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.

CVE-2025-20968
Samsung Gallery General
7.2
HIGH
EPSS
0.3%
2025 1 PoC

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows remote attackers to access data and perform internal operations within Samsung Gallery.

CVE-2025-46657
Karazal Web
7.2
HIGH
EPSS
0.1%
2025 CWE-79 2 PoCs

Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.

CVE-2025-12399
Alex Reservations: Smart Restaurant Booking Web Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-434 2 PoCs

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-41674
mbNET.mini General
7.2
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.

CVE-2025-14097
ABL90 FLEX and ABL90 FLEX PLUS Analyzers General
7.2
HIGH
EPSS
0.4%
2025 CWE-287 1 PoC

A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthorized device management when specific internal conditions are met. Exploitation requires that a remote connection is established with additional information obtained through other means. The issue is caused by a weakness in the analyzer’s application software.                                                                                                                                                                                                Other related CVE's are CVE-

CVE-2025-3944
Niagara Framework General
7.2
HIGH
EPSS
0.3%
2025 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-36729
M!DGE2 General
7.2
HIGH
EPSS
0.1%
2025 CWE-269 1 PoC

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.

CVE-2025-54478
Mattermost Confluence Plugin Web
7.2
HIGH
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

CVE-2025-52519
Software Genérico General
7.1
HIGH
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Improper validation of user-space input in the issimian device driver leads to information disclosure and a denial of service.

CVE-2025-63711
Software Genérico Web
7.1
HIGH
EPSS
0.1%
2025 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_delete.php) accepts POST requests containing a user_id parameter and does not enforce request origin or anti-CSRF tokens. Because the endpoint lacks proper authentication/authorization checks and CSRF protections, a remote attacker can craft a malicious page that triggers deletion when visited by an auth

CVE-2025-0468
Graphics DDK General
7.1
HIGH
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.