9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-30154
🔥 KEV reviewdog General
8.6
HIGH
EPSS
34.0%
2025 CWE-506 1 PoC

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.

CVE-2025-53418
COMMGR General
8.6
HIGH
EPSS
0.1%
2025 CWE-121 1 PoC

Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.

CVE-2025-27222
Software Genérico General ⚡ nuclei
8.6
HIGH
EPSS
5.1%
2025 1 PoC

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to read any local server file that is accessible by the TRUfusion user and can also be used to leak cleartext passwords of TRUfusion Enterprise itself.

CVE-2025-1424
InkPad Color 3 General
8.6
HIGH
EPSS
0.1%
2025 CWE-269 1 PoC

A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the device. This issue affects InkPad Color 3 in version U743k3.6.8.3671.

CVE-2025-43994
Dell Storage Manager General
8.6
HIGH
EPSS
0.1%
2025 CWE-306 1 PoC

Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

CVE-2025-0994
🔥 KEV Cityworks General
8.6
HIGH
EPSS
74.9%
2025 CWE-502 1 PoC

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.

CVE-2025-34197
Print Virtual Appliance Host General
8.6
HIGH
EPSS
0.0%
2025 CWE-798 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubuntu ALL=(ALL) NOPASSWD: ALL). Anyone who knows the hardcoded password can obtain root privileges via local console or equivalent administrative access, enabling local privilege escalation. This vulnerability has been identified by the vendor as: V-2024-010 — Hardcoded Linux Password. NOTE: The patch

CVE-2025-5309
Remote support & Privileged Remote Access General
8.6
HIGH
EPSS
1.4%
2025 CWE-94 1 PoC

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

CVE-2025-12816
node-forge General
8.6
HIGH
EPSS
0.1%
2025 2 PoCs

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

CVE-2025-7766
Provisioning Manager General
8.6
HIGH
EPSS
0.3%
2025 CWE-611 2 PoCs

Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.

CVE-2025-7012
Cato Client General
8.6
HIGH
EPSS
0.1%
2025 CWE-59 1 PoC

An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.

CVE-2025-4680
upKeeper Instant Privilege Access General
8.6
HIGH
EPSS
0.1%
2025 CWE-20 1 PoC

Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects upKeeper Instant Privilege Access: before 1.4.0.

CVE-2025-34200
Print Virtual Appliance Host General
8.6
HIGH
EPSS
0.0%
2025 CWE-312 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the appliance with the network account credentials in clear-text inside /etc/issue, and the file is world-readable by default. An attacker with local shell access can read /etc/issue to obtain the network account username and password. Using the network account an attacker can change network parameters via the appliance interface, enabling local misconfiguration, network disruption or further escalation depending on deployment.

CVE-2020-7678
node-import General
8.6
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".

CVE-2020-4567
Security Key Lifecycle Manager General
8.6
HIGH
EPSS
0.6%
2020 1 PoC

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.

CVE-2020-36881
DiskBoss General
8.6
HIGH
EPSS
0.0%
2020 CWE-119 1 PoC

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to execute arbitrary code on the system. Attackers can exploit this by pasting a specially crafted directory path into the 'Add Input Directory' field.

CVE-2020-1764
kiali General
8.6
HIGH
EPSS
6.1%
2020 CWE-321 1 PoC

A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio configuration.

CVE-2020-28449
decal General
8.6
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package decal. The vulnerability is in the set function.

CVE-2020-11303
Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
8.6
HIGH
EPSS
0.2%
2020 1 PoC

Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2020-28494
total.js General
8.6
HIGH
EPSS
1.2%
2020 1 PoC

This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue occurs because child_process.spawn is called with the option shell set to true and because the type parameter is not properly sanitized.