5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-27647
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users Without Authentication V-2024-002.

CVE-2025-57119
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function

CVE-2025-27645
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting HTTP Permission Methods on the Server Side V-2024-005.

CVE-2025-1044
Unified SecOps Platform General
9.8
CRITICAL
EPSS
0.4%
2025 CWE-287 1 PoC

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336.

CVE-2025-25763
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

CVE-2025-6934
Opal Estate Pro – Property Management and Submission Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
28.0%
2025 CWE-269 9 PoCs

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.

CVE-2025-28405
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

CVE-2025-45065
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 3 PoCs

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

CVE-2025-65856
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2025 1 PoC

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling direct unauthorized video stream access.

CVE-2025-11953
🔥 KEV Software Genérico Windows
9.8
CRITICAL
EPSS
18.6%
2025 CWE-78 1 PoC

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

CVE-2025-53770
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.5%
2025 CWE-502 46 PoCs

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

CVE-2025-56218
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

CVE-2025-30444
macOS Windows
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Mounting a maliciously crafted SMB network share may lead to system termination.

CVE-2025-1793
run-llama/llama_index Database
9.8
CRITICAL
EPSS
0.1%
2025 CWE-89 1 PoC

Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.

CVE-2025-44890
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.

CVE-2025-1661
HUSKY – Products Filter Professional for WooCommerce Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2025 CWE-22 3 PoCs

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2025-55835
Software Genérico Web
9.8
CRITICAL
EPSS
1.3%
2025 1 PoC

File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.

CVE-2025-7401
Premium Age Verification / Restriction for WordPress Web Windows
9.8
CRITICAL
EPSS
1.9%
2025 CWE-798 1 PoC

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVE-2025-57515
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to inject arbitrary SQL commands via vulnerable input fields, enabling the execution of time-delay functions to infer database responses.

CVE-2025-1066
OpenPLC General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.