5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-55998
Software Genérico Web
8.1
HIGH
EPSS
0.0%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter

CVE-2025-27480
Windows Server 2012 Windows
8.1
HIGH
EPSS
0.8%
2025 CWE-416 2 PoCs

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

CVE-2025-3515
Drag and Drop Multiple File Upload for Contact Form 7 Web Windows ⚡ nuclei
8.1
HIGH
EPSS
4.6%
2025 CWE-434 6 PoCs

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other dangerous file types on the affected site's server, which may make remote code execution possible on the servers that are configured to handle .phar files as executable PHP scripts, particularly in default Apache+mod_php configurations where the file extension is not strictly vali

CVE-2025-48416
cPH2 / cPP2 charging stations Networking
8.1
HIGH
EPSS
0.3%
2025 CWE-912 2 PoCs

An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image for the "root" user. However, in the default SSH configuration the "PermitRootLogin" is disabled, preventing the root user from logging in via SSH. This configuration can be bypassed/changed by an attacker through multiple paths though.

CVE-2025-48384
🔥 KEV git General
8.1
HIGH
EPSS
0.6%
2025 CWE-436 42 PoCs

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the alter

CVE-2025-58075
Mattermost General
8.1
HIGH
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState

CVE-2025-29314
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 1 PoC

Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to access sensitive information via a man-in-the-middle attack.

CVE-2025-0749
Homey Web Windows
8.1
HIGH
EPSS
0.0%
2025 CWE-288 1 PoC

The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user.

CVE-2025-6445
ServiceStack General
8.1
HIGH
EPSS
0.9%
2025 CWE-22 1 PoC

ServiceStack FindType Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ServiceStack. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of the FindType method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the cur

CVE-2025-8036
Firefox General
8.1
HIGH
EPSS
0.1%
2025 1 PoC

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

CVE-2025-50105
Oracle Universal Work Queue Web Database
8.1
HIGH
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as unauthorized access to critical data or complete access to all Oracle Universal Work Qu

CVE-2025-35940
Archiver Web
8.1
HIGH
EPSS
0.3%
2025 CWE-798 1 PoC

The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL endpoints.

CVE-2025-1094
PostgreSQL Database
8.1
HIGH
EPSS
82.4%
2025 CWE-149 5 PoCs

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding

CVE-2025-25477
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 1 PoC

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

CVE-2025-1193
Remote Desktop Manager Windows
8.1
HIGH
EPSS
0.2%
2025 CWE-295 1 PoC

Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host.

CVE-2025-55741
unopim Web
8.1
HIGH
EPSS
0.1%
2025 CWE-284 1 PoC

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete privilege for products are unable to delete individual products via the standard endpoint, as expected. However, these users can bypass intended access controls by issuing requests to the mass-delete endpoint, allowing them to delete products without proper authorization. This vulnerability allows unauthorized product deletion, leading to potential data loss and business disruption. The issue is fixed in version 0.3.1. No known workarounds

CVE-2025-58073
Mattermost General
8.1
HIGH
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state.

CVE-2025-30712
Oracle VM VirtualBox Database
8.1
HIGH
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox access

CVE-2025-32710
Windows Server 2008 R2 Service Pack 1 Windows
8.1
HIGH
EPSS
0.7%
2025 CWE-416 1 PoC

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVE-2025-68472
mindsdb Web
8.1
HIGH
EPSS
0.4%
2025 CWE-22 1 PoC

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing sensitive data. The PUT handler in file.py directly joins user-controlled data into a filesystem path when the request body is JSON and source_type is not "url". Only multipart uploads and URL-sourced uploads receive sanitization; JSON uploads lack any call to clear_filename or equivalent checks. This vulnerability is fixed