5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-13631
Chrome General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High)

CVE-2025-5280
Chrome General
8.8
HIGH
EPSS
0.6%
2025 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-10201
Chrome General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVE-2025-60991
Software Genérico Web
8.8
HIGH
EPSS
0.0%
2025 1 PoC

A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload injected into the cat parameter.

CVE-2025-32451
Foxit Reader Web
8.8
HIGH
EPSS
0.2%
2025 CWE-824 2 PoCs

A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2025-59106
Access Manager 92xx-k7 General
8.8
HIGH
EPSS
0.1%
2025 CWE-272 2 PoCs

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

CVE-2025-62549
Windows 10 Version 1607 Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-822 2 PoCs

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-56079
Software Genérico General
8.8
HIGH
EPSS
0.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1.00/V2.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-21043
🔥 KEV Samsung Mobile Devices General
8.8
HIGH
EPSS
4.9%
2025 1 PoC

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CVE-2025-66953
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2025 1 PoC

CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interface and specifically the /system_setup.htm, /set_clock.htm, /receiver_setup.htm, /cal.htm?..., and /channel_setup.htm endpoints

CVE-2025-53558
ZXHN-F660T General ⚡ nuclei
8.8
HIGH
EPSS
13.1%
2025 CWE-1391 0 PoCs

ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.

CVE-2025-5068
Chrome General
8.8
HIGH
EPSS
0.4%
2025 CWE-416 1 PoC

Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-8109
Graphics DDK General
8.8
HIGH
EPSS
0.0%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory.

CVE-2025-57278
Software Genérico Networking
8.8
HIGH
EPSS
0.1%
2025 1 PoC

The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, the router grants access to any other client using that same IP, without requiring credentials or verifying client identity. There are no session tokens, cookies, or unique identifiers in place. This flaw allows an attacker to obtain full administrative access simply by configuring their device to use the same IP address as a previously authenticated user. This results in a complete authentication b

CVE-2025-54920
Apache Spark Web
8.8
HIGH
EPSS
0.5%
2025 CWE-502 1 PoC

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to overly permissive Jackson deserialization of event log data. This allows an attacker with access to the Spark event logs directory to inject malicious JSON payloads that trigger deserialization of arbitrary classes, enabling command execution on the host running the Spark History Server. Details The vulnerability a

CVE-2025-28357
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2025 1 PoC

A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted HTTP request.

CVE-2025-14174
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.4%
2025 1 PoC

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2025-24381
Unity General
8.8
HIGH
EPSS
0.4%
2025 CWE-601 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information. Exploitation may allow for session theft.

CVE-2025-55345
Software Genérico General
8.8
HIGH
EPSS
0.5%
2025 CWE-61 1 PoC

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

CVE-2025-65271
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an administrator's session. This can occur via plugins or dashboard components that render untrusted user input, potentially enabling privilege escalation to an administrative account. Fixed in Azuriom 1.2.7.