5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-30114
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can bypass the authentication process and gain full access to the dashcam's features without proper authorization.

CVE-2025-23097
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.

CVE-2025-22604
cacti General
9.1
CRITICAL
EPSS
70.5%
2025 CWE-78 1 PoC

Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as part of a system command, causing a command execution vulnerability. This vulnerability is fixed in 1.2.29.

CVE-2025-69690
Software Genérico Web
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.

CVE-2025-45006
Software Genérico Networking
9.1
CRITICAL
EPSS
0.2%
2025 1 PoC

Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks.

CVE-2025-9943
Service Provider Web Database
9.1
CRITICAL
EPSS
0.2%
2025 CWE-89 2 PoCs

An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attacker can exploit this issue via blind SQL injection, allowing for the extraction of arbitrary data from the database, if the database connection is configured to use the ODBC plugin. The vulnerability arises from insufficient escaping of single quotes in the class SQLString (file odbc-store.cpp, lines 253-271). This issue affects Shibboleth Service Provider thr

CVE-2025-23099
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

CVE-2025-32118
CMP – Coming Soon & Maintenance General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.

CVE-2025-5098
PrinterShare Mobile Print General
9.1
CRITICAL
EPSS
0.1%
2025 CWE-200 1 PoC

PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization.

CVE-2025-28915
ThemeEgg ToolKit General
9.1
CRITICAL
EPSS
24.9%
2025 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Server.This issue affects ThemeEgg ToolKit: from n/a through <= 1.2.9.

CVE-2025-22940
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 2 PoCs

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

CVE-2025-54677
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
9.1
CRITICAL
EPSS
0.1%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Malicious Files.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.3.

CVE-2025-65548
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage when the token is spent. The preimage is stored by the mint and attacker can exploit this vulnerability to fill the mint's db nd disk with arbitrary data.

CVE-2025-32206
Processing Projects General
9.1
CRITICAL
EPSS
0.2%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Server.This issue affects Processing Projects: from n/a through <= 1.0.2.

CVE-2025-14829
E-xact | Hosted Payment | Web Windows
9.1
CRITICAL
EPSS
0.1%
2025 1 PoC

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

CVE-2025-28232
Software Genérico Web
9.1
CRITICAL
EPSS
0.2%
2025 1 PoC

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

CVE-2025-24383
Unity General
9.1
CRITICAL
EPSS
1.5%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delete critical system files as root. Dell recommends customers to upgrade at the earliest opportunity.

CVE-2025-25948
Software Genérico General
9.1
CRITICAL
EPSS
3.2%
2025 1 PoC

Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

CVE-2025-23968
AiBud WP General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through <= 1.9.

CVE-2025-70146
Software Genérico Web
9.1
CRITICAL
EPSS
0.6%
2025 1 PoC

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.