94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-55619
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.

CVE-2025-4822
ScadaWatt Otopilot Database
9.8
CRITICAL
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection.This issue affects ScadaWatt Otopilot: before 27.05.2025.

CVE-2025-65354
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise.

CVE-2025-46811
Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1 DevOps Cloud
9.8
CRITICAL
EPSS
3.1%
2025 CWE-862 2 PoCs

A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE: from ? before 4.3

CVE-2025-28137
Software Genérico General
9.8
CRITICAL
EPSS
11.9%
2025 3 PoCs

The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

CVE-2025-1562
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
19.5%
2025 CWE-862 1 PoC

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_or_activate_addon_plugins() function and a weak nonce hash in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated attackers to install arbitrary plugins on the site that can be leveraged to further infect a vulnerable site.

CVE-2025-24195
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to elevate privileges.

CVE-2025-29085
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
22.6%
2025 0 PoCs

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

CVE-2025-57118
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php

CVE-2025-65834
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulated width and height parameters. By setting these values to extremely large numbers, the application attempts to allocate excessive memory during image processing, triggering a buffer overflow in the mlt_image_fill_white function.

CVE-2025-53693
Sitecore Experience Manager (XM) General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-470 3 PoCs

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.

CVE-2020-10826
Software Genérico Web
9.8
CRITICAL
EPSS
30.0%
2020 2 PoCs

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.

CVE-2020-7719
locutus Web
9.8
CRITICAL
EPSS
1.7%
2020 2 PoCs

Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

CVE-2020-29007
Software Genérico General
9.8
CRITICAL
EPSS
17.4%
2020 1 PoC

The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.

CVE-2020-7781
connection-tester General
9.8
CRITICAL
EPSS
0.6%
2020 1 PoC

This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:

CVE-2020-28451
image-tiler General
9.8
CRITICAL
EPSS
0.6%
2020 1 PoC

This affects the package image-tiler before 2.0.2.

CVE-2020-14756
Utilities Framework Database
9.8
CRITICAL
EPSS
83.4%
2020 3 PoCs

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-6094
Accusoft General
9.8
CRITICAL
EPSS
1.4%
2020 CWE-190 1 PoC

An exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Accusoft ImageGear 19.4, 19.5 and 19.6. A specially crafted TIFF file can cause an out-of-bounds write, resulting in remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-12500
P+F Comtrol RocketLinx General
9.8
CRITICAL
EPSS
0.8%
2020 CWE-306 4 PoCs

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.

CVE-2020-12641
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.1%
2020 2 PoCs

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.