94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-55575
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with action=service_detail.

CVE-2025-63223
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2025 1 PoC

The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system settings, leading to full compromise of the device.

CVE-2025-44887
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

CVE-2025-28399
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

CVE-2025-44658
Software Genérico Web
9.8
CRITICAL
EPSS
0.5%
2025 1 PoC

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.

CVE-2025-4688
SINAV.LINK Exam Result Module Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection.This issue affects SINAV.LINK Exam Result Module: before 1.2.

CVE-2025-1066
OpenPLC General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.

CVE-2025-31651
Apache Tomcat Web
9.8
CRITICAL
EPSS
0.4%
2025 CWE-116 1 PoC

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL vers

CVE-2025-46120
Software Genérico General
9.8
CRITICAL
EPSS
2.5%
2025 1 PoC

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.

CVE-2025-27638
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Hardcoded Password V-2024-013.

CVE-2025-52095
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll

CVE-2025-10294
OwnID Passwordless Login Web Windows
9.8
CRITICAL
EPSS
0.5%
2025 CWE-288 2 PoCs

The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to log in as other users, including administrators, on instances where the plugin has not been fully configured yet.

CVE-2025-4094
DIGITS: WordPress Mobile Number Signup and Login Web Windows
9.8
CRITICAL
EPSS
3.0%
2025 3 PoCs

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.

CVE-2025-49388
Miraculous Core Plugin General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Escalation.This issue affects Miraculous Core Plugin: from n/a through <= 2.0.7.

CVE-2025-50460
Software Genérico General
9.8
CRITICAL
EPSS
4.1%
2025 1 PoC

A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.load() from the PyYAML library (versions = 5.3.1). If an attacker can control the content of the YAML configuration file passed to the --run_config parameter, arbitrary code can be executed during deserialization. This can lead to full system compromise. The vulnerability is triggered when a malicious YAML file is loaded, allowing the execution of arbitrary Python commands such as os.system(). It is recommended to upgrade PyYAML to version 5.4 or hig

CVE-2025-0180
WP Foodbakery Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 CWE-269 1 PoC

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.

CVE-2025-57515
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to inject arbitrary SQL commands via vulnerable input fields, enabling the execution of time-delay functions to infer database responses.

CVE-2025-47981
Windows 10 Version 1507 Windows
9.8
CRITICAL
EPSS
3.2%
2025 CWE-122 2 PoCs

Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

CVE-2025-5319
DIGITA Efficiency Management System Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System allows SQL Injection.This issue affects DIGITA Efficiency Management System: through 03022026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-5329
Delta Course Automation Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection.This issue affects Delta Course Automation: through 04022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.