5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-66953
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2025 1 PoC

CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interface and specifically the /system_setup.htm, /set_clock.htm, /receiver_setup.htm, /cal.htm?..., and /channel_setup.htm endpoints

CVE-2025-65271
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an administrator's session. This can occur via plugins or dashboard components that render untrusted user input, potentially enabling privilege escalation to an administrative account. Fixed in Azuriom 1.2.7.

CVE-2025-0592
SICK Lector8xx General
8.8
HIGH
EPSS
0.1%
2025 CWE-924 1 PoC

The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device.

CVE-2025-52914
Software Genérico Database
8.8
HIGH
EPSS
0.1%
2025 1 PoC

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary SQL database commands.

CVE-2025-0436
Chrome General
8.8
HIGH
EPSS
0.5%
2025 CWE-472 1 PoC

Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-7049
WPGYM - Wordpress Gym Management System Web Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-639 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_add_user' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the email, password, and other details of any user, including Administrator users.

CVE-2025-28357
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2025 1 PoC

A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted HTTP request.

CVE-2025-1304
NewsBlogger Web Windows
8.8
HIGH
EPSS
1.5%
2025 CWE-862 1 PoC

The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-21043
🔥 KEV Samsung Mobile Devices General
8.8
HIGH
EPSS
4.9%
2025 1 PoC

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CVE-2025-2073
ChromeOS General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure

CVE-2025-13631
Chrome General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High)

CVE-2025-51480
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.

CVE-2025-58411
Graphics DDK General
8.8
HIGH
EPSS
0.0%
2025 CWE-416 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused scenario where potential write use after free was present.

CVE-2025-65817
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.

CVE-2025-55164
content-security-policy-parser General
8.8
HIGH
EPSS
0.2%
2025 CWE-1321 1 PoC

content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This issue has been patched in version 0.6.0. A workaround involves disabling prototype method in NodeJS, neutralizing all possible prototype pollution attacks. Provide either --disable-proto=delete (recommended) or --disable-proto=throw as an argument to node to enable this feature.

CVE-2025-32061
Infotainment system ECU General
8.8
HIGH
EPSS
0.0%
2025 CWE-121 2 PoCs

The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper layer L2CAP channel. An attacker can leverage this vulnerability to obtain remote code execution on the Infotainment ECU with root privileges. First identified on Nissan Leaf ZE1 manufactured in 2020.

CVE-2025-55345
Software Genérico General
8.8
HIGH
EPSS
0.5%
2025 CWE-61 1 PoC

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

CVE-2025-1918
Chrome General
8.8
HIGH
EPSS
0.7%
2025 CWE-125 1 PoC

Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Medium)

CVE-2025-51991
Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
3.7%
2025 0 PoCs

XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity template code, which is rendered on the server side without proper validation or sandboxing. This enables the execution of arbitrary template logic, which may expose internal server information or, in specific configurations, lead to further exploitation such as remote code execution or sensitive data leakage. The vulnerab