Base de datos CVE
Archivo de vulnerabilidades conocidas (CVE) con puntuación CVSS, gravedad, productos y fabricantes afectados. Filtra por año y severidad.
- CVE-2025-1976Media6.7
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
- CVE-2025-34028Crítica10.0
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
- CVE-2025-42599Crítica9.8
Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.
- CVE-2025-32433Crítica10.0
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
- CVE-2025-31201Crítica9.8
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
- CVE-2025-31200Crítica9.8
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
- CVE-2024-58136Crítica9.0
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
- CVE-2025-29824Alta7.8
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-3248Crítica9.8
Las versiones de Langflow anteriores a 1.3.0 son susceptibles a inyección de código en el endpoint /api/v1/validate/code. Un atacante remoto y no autenticado puede enviar solicitudes HTTP manipuladas para ejecutar código arbitrario.
- CVE-2025-31161Crítica9.8
CrushFTP 10 anterior a 10.8.4 y 11 anterior a 11.3.1 permite la omisión de autenticación y la toma de control de la cuenta crushadmin (a menos que se utilice una instancia proxy DMZ), tal como se ha explotado en entornos reales en marzo y abril de 2025, también conocido como «acceso no autenticado al puerto HTTP(S)». Existe una condición de carrera en el método de autorización AWS4-HMAC (compatible con S3) del componente HTTP del servidor FTP. El servidor primero verifica la existencia del usuario realizando una llamada a login_user_pass() sin requisito de contraseña. Esto autenticará la sesión mediante el proceso de verificación HMAC y hasta que el servidor compruebe la verificación del usuario una vez más. La vulnerabilidad se puede estabilizar aún más, eliminando la necesidad de desencadenar con éxito una condición de carrera, mediante el envío de una cabecera AWS4-HMAC malformada. Al proporcionar solo el nombre de usuario y una barra inclinada (/), el servidor encontrará con éxito un nombre de usuario, lo que desencadena el proceso de autenticación anypass correcto, pero el servidor no podrá encontrar la entrada SignedHeaders esperada, lo que provoca un error de índice fuera de los límites que impide que el código llegue a la limpieza de la sesión. En conjunto, estos problemas hacen que sea trivial autenticarse como cualquier usuario conocido o adivinable (por ejemplo, crushadmin) y pueden conducir a un compromiso total del sistema mediante la obtención de una cuenta administrativa.
- CVE-2025-30406Crítica9.0
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.
- CVE-2025-22457Crítica9.0
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
- CVE-2025-31125Media5.3
Vite es un framework de herramientas frontend para javascript. Vite expone el contenido de archivos no permitidos mediante ?inline&import o ?raw?import. Solo las aplicaciones que exponen explícitamente el servidor dev de Vite a la red (mediante la opción de configuración --host o server.host) están afectadas. Esta vulnerabilidad está corregida en 6.2.4, 6.1.3, 6.0.13, 5.4.16 y 4.5.11.
- CVE-2025-2894Media6.6
El Go1, también conocido como "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level", contiene una puerta trasera no documentada que puede permitir al fabricante, y a cualquier persona en posesión de la clave API correcta, el control remoto completo sobre el dispositivo robótico afectado utilizando el servicio de acceso remoto CloudSail.
- CVE-2025-2783Alta8.3
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)
- CVE-2025-29635Alta7.2
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
- CVE-2025-2749Alta7.2
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
- CVE-2025-2747Crítica9.8
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.
- CVE-2025-2746Crítica9.8
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
- CVE-2025-30208Media5.3
Vite, un proveedor de herramientas de desarrollo frontend, presenta una vulnerabilidad en las versiones anteriores a 6.2.3, 6.1.2, 6.0.12, 5.4.15 y 4.5.10. `@fs` deniega el acceso a archivos fuera de la lista de permitidos del servidor de Vite. Añadir `?raw??` o `?import&raw??` a la URL omite esta limitación y devuelve el contenido del archivo si existe. Este bypass existe porque los separadores finales, como `?`, se eliminan en varios lugares, pero no se tienen en cuenta en las expresiones regulares de las cadenas de consulta. El contenido de archivos arbitrarios puede devolverse al navegador. Solo se ven afectadas las aplicaciones que exponen explícitamente el servidor de desarrollo de Vite a la red (usando `--host` o la opción de configuración `server.host`). Las versiones 6.2.3, 6.1.2, 6.0.12, 5.4.15 y 4.5.10 corrigen el problema.
This product uses the NVD API but is not endorsed or certified by the NVD.