Base de datos CVE
Archivo de vulnerabilidades conocidas (CVE) con puntuación CVSS, gravedad, productos y fabricantes afectados. Filtra por año y severidad.
- CVE-2025-10585Crítica9.8
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-26399Crítica9.8
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
- CVE-2025-59689Media6.1
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
- CVE-2025-48703Crítica9.0
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
- CVE-2025-10035Crítica10.0
Una vulnerabilidad de deserialización en el License Servlet de GoAnywhere MFT de Fortra permite a un actor con una firma de respuesta de licencia falsificada válidamente deserializar un objeto arbitrario controlado por el actor, lo que posiblemente conduce a la inyección de comandos.
- CVE-2025-9242Crítica9.8
Una vulnerabilidad de escritura fuera de los límites en el proceso iked de WatchGuard Fireware OS puede permitir que un atacante remoto no autenticado ejecute código arbitrario. Esta vulnerabilidad afecta tanto a la VPN de usuario móvil con IKEv2 como a la VPN de sucursal que utiliza IKEv2 cuando se configura con un peer de puerta de enlace dinámico. Si el Firebox se configuró previamente con la VPN de usuario móvil con IKEv2 o con una VPN de sucursal que utiliza IKEv2 hacia un peer de puerta de enlace dinámico, y ambas configuraciones se han eliminado desde entonces, ese Firebox puede seguir siendo vulnerable si todavía está configurada una VPN de sucursal hacia un peer de puerta de enlace estático.
- CVE-2025-21043Alta8.8
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
- CVE-2025-21042Alta8.8
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
- CVE-2025-54236Crítica9.1
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
- CVE-2025-55241Crítica10.0
Vulnerabilidad de elevación de privilegios en Azure Entra ID
- CVE-2025-48543Alta8.8
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-53690Crítica9.0
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
- CVE-2025-9377Alta7.2
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).
- CVE-2025-55177Media5.4
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
- CVE-2025-57819Crítica9.8
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
- CVE-2025-7775Crítica9.8
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX
- CVE-2025-43300Crítica10.0
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
- CVE-2025-8876Alta8.8
Vulnerabilidad de validación de entrada incorrecta en N-able N-central permite la inyección de comandos del sistema operativo. Este problema afecta a N-central: antes de 2025.3.1.
- CVE-2025-8875Alta7.8
Vulnerabilidad de deserialización de datos no confiables en N-able N-central permite la ejecución local de código. Este problema afecta a N-central: antes de 2025.3.1.
- CVE-2025-8714Alta8.8
La inclusión de datos no confiables en pg_dump en PostgreSQL permite a un superusuario malicioso del servidor de origen inyectar código arbitrario para su ejecución en el momento de la restauración como la cuenta del sistema operativo del cliente que ejecuta psql para restaurar el volcado, a través de metacomandos de psql. pg_dumpall también está afectado. pg_restore está afectado cuando se utiliza para generar un volcado en formato plano. Esto es similar a MySQL CVE-2024-21096. Las versiones anteriores a PostgreSQL 17.6, 16.10, 15.14, 14.19 y 13.22 están afectadas.
This product uses the NVD API but is not endorsed or certified by the NVD.