9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-3947
C300 PCNT02 General
8.2
HIGH
EPSS
0.4%
2025 CWE-191 1 PoC

The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in improper integer data value checking during subtraction leading to a denial of service. Honeywell recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1. The affected Experion PKS products are C300 PCNT02, C300 PCNT05, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are

CVE-2025-3192
spatie/browsershot General
8.2
HIGH
EPSS
0.3%
2025 CWE-918 1 PoC

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.

CVE-2025-57773
dataease General
8.2
HIGH
EPSS
0.4%
2025 CWE-502 1 PoC

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, writing to various files. This vulnerability requires commons-collections 4.x and aspectjweaver-1.9.22.jar. The vulnerability has been fixed in version 2.10.12.

CVE-2025-8267
ssrfcheck General
8.2
HIGH
EPSS
0.1%
2025 CWE-918 1 PoC

Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address ranges. Specifically, the package fails to classify the reserved IP address space 224.0.0.0/4 (Multicast) as invalid. This oversight allows attackers to craft requests targeting these multicast addresses.

CVE-2025-8020
private-ip General
8.2
HIGH
EPSS
0.0%
2025 CWE-918 1 PoC

All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that resolves to a multicast IP address (224.0.0.0/4) which is not included as part of the private IP ranges in the package's source code.

CVE-2025-1022
spatie/browsershot General
8.2
HIGH
EPSS
0.2%
2025 CWE-20 1 PoC

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../../../etc/passwd). This is due to missing validations of the user input that should be blocking file URI schemes (e.g., file:// and file:/) in the HTML content.

CVE-2025-65001
fbiosdrv.sys General
8.2
HIGH
EPSS
0.0%
2025 CWE-787 1 PoC

Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and availability.

CVE-2025-60017
Go2 General
8.2
HIGH
EPSS
0.0%
2025 CWE-78 1 PoC

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).

CVE-2025-46067
Software Genérico General
8.2
HIGH
EPSS
0.1%
2025 1 PoC

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file

CVE-2025-3052
BiosFlashShell General
8.2
HIGH
EPSS
0.1%
2025 1 PoC

An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.

CVE-2025-32966
dataease General ⚡ nuclei
8.2
HIGH
EPSS
11.2%
2025 CWE-290 0 PoCs

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.

CVE-2025-61553
Software Genérico General
8.2
HIGH
EPSS
0.0%
2025 1 PoC

An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration space access. Given it's a heap overflow in a privileged hypervisor context, exploitation may enable arbitrary code execution or guest-to-host privilege escalation.

CVE-2025-1533
Armoury Crate General
8.2
HIGH
EPSS
0.1%
2025 CWE-121 1 PoC

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

CVE-2025-0611
Chrome General
8.2
HIGH
EPSS
0.6%
2025 1 PoC

Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-0467
Graphics DDK General
8.2
HIGH
EPSS
0.1%
2025 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVE-2025-2691
nossrf General
8.2
HIGH
EPSS
0.0%
2025 CWE-918 1 PoC

Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.

CVE-2025-52461
libbiosig General
8.2
HIGH
EPSS
0.1%
2025 CWE-125 2 PoCs

An out-of-bounds read vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-22381
Software Genérico General
8.2
HIGH
EPSS
0.0%
2025 1 PoC

Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.

CVE-2025-10184
OxygenOS General
8.2
HIGH
EPSS
0.2%
2025 CWE-862 7 PoCs

The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to sensitive information disclosure and could effectively break the security provided by SMS-based Multi-Factor Authentication (MFA) checks. The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.tele

CVE-2025-52164
Software Genérico General
8.2
HIGH
EPSS
0.1%
2025 1 PoC

Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.