94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-4603
eMagicOne Store Manager for WooCommerce Web Windows
9.1
CRITICAL
EPSS
3.0%
2025 CWE-73 3 PoCs

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is only exploitable by unauthenticated attackers in default configurations where the the default password is left as 1:1, or where the attacker gains access to the credentials.

CVE-2025-25014
Kibana Web
9.1
CRITICAL
EPSS
2.5%
2025 CWE-1321 2 PoCs

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

CVE-2025-15484
Order Notification for WooCommerce Web Windows
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

CVE-2025-65318
Software Genérico Windows
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.

CVE-2025-6205
🔥 KEV DELMIA Apriso General ⚡ nuclei
9.1
CRITICAL
EPSS
77.7%
2025 CWE-862 0 PoCs

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

CVE-2025-29927
next.js General ⚡ nuclei
9.1
CRITICAL
EPSS
92.1%
2025 CWE-285 98 PoCs

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

CVE-2025-70146
Software Genérico Web
9.1
CRITICAL
EPSS
0.6%
2025 1 PoC

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.

CVE-2025-32206
Processing Projects General
9.1
CRITICAL
EPSS
0.2%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Server.This issue affects Processing Projects: from n/a through <= 1.0.2.

CVE-2025-22940
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 2 PoCs

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

CVE-2025-32118
CMP – Coming Soon & Maintenance General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.

CVE-2025-66945
Software Genérico Web
9.1
CRITICAL
EPSS
0.2%
2025 1 PoC

A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outside the intended directory, leading to arbitrary file overwrite and potentially remote code execution

CVE-2025-39436
I Draw General
9.1
CRITICAL
EPSS
0.1%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0.

CVE-2025-63416
Software Genérico Web
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated low-privileged attackers to execute arbitrary JavaScript in the context of other users' sessions. This can be exploited to access administrative data and functions, leading to privilege escalation and full compromise of sensitive user data, as demonstrated by the ability to fetch and exfiltrate the contents of the /admin/users endpoint.

CVE-2025-52390
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to manipulate the SQL logic and potentially extract sensitive information or escalate their privileges.

CVE-2025-56231
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

CVE-2025-65346
Software Genérico Web
9.1
CRITICAL
EPSS
0.2%
2025 2 PoCs

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths.

CVE-2025-25948
Software Genérico General
9.1
CRITICAL
EPSS
3.2%
2025 1 PoC

Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

CVE-2025-23968
AiBud WP General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through <= 1.9.

CVE-2025-28915
ThemeEgg ToolKit General
9.1
CRITICAL
EPSS
24.9%
2025 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Server.This issue affects ThemeEgg ToolKit: from n/a through <= 1.2.9.

CVE-2025-46271
UNI-NMS-Lite General
9.1
CRITICAL
EPSS
5.7%
2025 CWE-78 1 PoC

UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.