94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-52688
OmniAccess Stellar Products General
9.8
CRITICAL
EPSS
0.2%
2025 CWE-77 2 PoCs

Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.

CVE-2025-7955
RingCentral Communications Plugin – FREE Web Windows
9.8
CRITICAL
EPSS
0.6%
2025 CWE-287 1 PoC

The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.

CVE-2025-65656
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

CVE-2025-63217
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.

CVE-2025-32880
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2025 3 PoCs

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication is not encrypted and allows sniffing and machine-in-the-middle attacks.

CVE-2025-56819
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
11.8%
2025 1 PoC

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

CVE-2025-70221
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.

CVE-2025-70152
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.

CVE-2025-46108
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.

CVE-2025-67135
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

CVE-2025-65235
Software Genérico Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function.

CVE-2025-61757
🔥 KEV Identity Manager Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
87.8%
2025 1 PoC

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2025-65482
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 3 PoCs

An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.

CVE-2025-25763
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

CVE-2025-6573
Graphics DDK General
9.8
CRITICAL
EPSS
0.2%
2025 CWE-280 1 PoC

Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).

CVE-2025-22408
Android General
9.8
CRITICAL
EPSS
2.0%
2025 1 PoC

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-25940
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2025 1 PoC

VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.

CVE-2025-28024
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi

CVE-2025-31161
🔥 KEV CrushFTP Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
86.2%
2025 CWE-305 20 PoCs

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible with S3) authorization method of the HTTP component of the FTP server. The server first verifies the existence of the user by performing a call to login_user_pass() with no password requirement. This will authenticate the session through the HMAC verification process and up until the server checks f

CVE-2025-52046
Software Genérico General
9.8
CRITICAL
EPSS
54.4%
2025 1 PoC

Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.