94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-43728
ThinOS 10 General
9.6
CRITICAL
EPSS
0.2%
2025 CWE-693 1 PoC

Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

CVE-2025-50754
Software Genérico Web
9.6
CRITICAL
EPSS
0.3%
2025 1 PoC

Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the template editor, upload and execute a PHP web shell on the server, leading to full remote code execution.

CVE-2025-10894
Software Genérico General
9.6
CRITICAL
EPSS
0.1%
2025 CWE-506 1 PoC

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

CVE-2025-30967
WPJobBoard Web
9.6
CRITICAL
EPSS
0.1%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.

CVE-2025-10283
bbot General
9.6
CRITICAL
EPSS
0.1%
2025 CWE-22 1 PoC

BBOT's gitdumper module could be abused to execute commands through a malicious git repository.

CVE-2025-10284
bbot General
9.6
CRITICAL
EPSS
0.2%
2025 CWE-22 1 PoC

BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.

CVE-2025-6514
Software Genérico General
9.6
CRITICAL
EPSS
6.2%
2025 CWE-78 2 PoCs

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL

CVE-2025-25101
Munk Sites Web
9.6
CRITICAL
EPSS
1.2%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.This issue affects Munk Sites: from n/a through <= 1.0.7.

CVE-2025-39601
Custom CSS, JS & PHP Web
9.6
CRITICAL
EPSS
0.0%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & PHP: from n/a through <= 2.4.1.

CVE-2025-32756
🔥 KEV FortiNDR Networking
9.6
CRITICAL
EPSS
41.6%
2025 CWE-121 6 PoCs

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a r

CVE-2025-32641
Anant Addons for Elementor Web
9.6
CRITICAL
EPSS
0.1%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forgery.This issue affects Anant Addons for Elementor: from n/a through <= 1.1.8.

CVE-2025-56683
Software Genérico Web
9.6
CRITICAL
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to execute arbitrary code via injecting arbitrary Javascript into a crafted README.md file.

CVE-2025-24490
Mattermost Database
9.6
CRITICAL
EPSS
0.5%
2025 CWE-89 1 PoC

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.

CVE-2025-53964
Software Genérico General
9.6
CRITICAL
EPSS
0.1%
2025 1 PoC

GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary and then searches for any term included in that dictionary.

CVE-2020-25067
Software Genérico General
9.6
CRITICAL
EPSS
1.2%
2020 1 PoC

NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.

CVE-2020-26907
Software Genérico General
9.6
CRITICAL
EPSS
0.4%
2020 1 PoC

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

CVE-2020-7357
Cayin CMS-SE Web
9.6
CRITICAL
EPSS
77.2%
2020 CWE-78 1 PoC

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.

CVE-2020-14705
GoldenGate Database
9.6
CRITICAL
EPSS
0.5%
2020 1 PoC

Vulnerability in the Oracle GoldenGate product of Oracle GoldenGate (component: Process Management). The supported version that is affected is Prior to 19.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate executes to compromise Oracle GoldenGate. While the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 9.6 (Confidential

CVE-2020-14439
Software Genérico General
9.6
CRITICAL
EPSS
0.6%
2020 1 PoC

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

CVE-2020-26902
Software Genérico General
9.6
CRITICAL
EPSS
1.2%
2020 1 PoC

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.