5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-13070
CSV to SortTable Web Windows
6.6
MEDIUM
EPSS
0.1%
2025 1 PoC

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

CVE-2025-55582
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dcp` and `signalc` without verifying integrity, authenticity, or permissions. An attacker with local filesystem access (via physical access, firmware modification, or debug interfaces) can replace these binaries with malicious payloads. The script executes these binaries as root in an infinite loop, leading to persistent privilege escalation and arbitrary code execution. This issue is mitigated in v1.09.02, but the product is officially End-of-Life

CVE-2025-23040
desktop General
6.6
MEDIUM
EPSS
1.6%
2025 CWE-522 1 PoC

GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform all network related operations (such as cloning, fetching, and pushing). When a user attempts to clone a repository GitHub Desktop will invoke `git clone` and when Git encounters a remote which requires authentication it will request the credentials for that remote host from GitH

CVE-2025-2819
GT-SoftControl General
6.6
MEDIUM
EPSS
0.0%
2025 CWE-434 1 PoC

There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.

CVE-2025-57305
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

CVE-2025-57428
Software Genérico Networking
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands.

CVE-2025-20149
IOS Networking
6.5
MEDIUM
EPSS
0.0%
2025 CWE-120 1 PoC

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the CLI prompt. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

CVE-2025-67115
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to read arbitrary files from the filesystem via crafted values in the log_type parameter to /logsave.htm.

CVE-2025-54603
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

CVE-2025-24948
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.

CVE-2025-9215
StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-22 2 PoCs

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the file_download() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-60693
Software Genérico Web Networking
6.5
MEDIUM
EPSS
2.3%
2025 2 PoCs

A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to six user-supplied CGI parameters matching <parameter>_0~5 into a fixed-size buffer (a2) without proper bounds checking, appending colon delimiters during concatenation. Remote attackers can exploit this vulnerability via specially crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.

CVE-2025-14545
YML for Yandex Market Web Windows
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation process.

CVE-2025-10720
WP Private Content Plus General
6.5
MEDIUM
EPSS
0.2%
2025 2 PoCs

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

CVE-2025-47906
os/exec General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

CVE-2025-27804
cPH2 / cPP2 charging stations Web
6.5
MEDIUM
EPSS
0.9%
2025 CWE-78 2 PoCs

Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted message to a certain MQTT topic arbitrary OS commands can be executed with root permissions.

CVE-2025-50688
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2025 1 PoC

A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uploaded, the attacker can trigger the execution of arbitrary commands on the target system, allowing for remote code execution. This could lead to escalation of privileges depending on the privileges of the web server process. The attack does not require physical access and can be conducted remotely, p

CVE-2025-67835
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality.

CVE-2025-14980
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin settings.

CVE-2025-44895
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.