9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-57227
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via placing a crafted executable file into a parent folder.

CVE-2025-24173
iOS and iPadOS General
7.8
HIGH
EPSS
0.0%
2025 4 PoCs

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.

CVE-2025-21062
Smart Switch General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.

CVE-2025-23386
openSUSE Tumbleweed General
7.8
HIGH
EPSS
0.1%
2025 CWE-276 1 PoC

A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1.

CVE-2025-43576
Acrobat Reader General
7.8
HIGH
EPSS
0.2%
2025 CWE-416 1 PoC

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2025-66499
Foxit PDF Reader General
7.8
HIGH
EPSS
0.1%
2025 CWE-190 1 PoC

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.

CVE-2025-22458
Endpoint Manager General
7.8
HIGH
EPSS
0.2%
2025 CWE-427 1 PoC

DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

CVE-2025-21692
Linux General
7.8
HIGH
EPSS
0.0%
2025 9 PoCs

In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ets qdisc OOB Indexing Haowei Yan <g1042620637@gmail.com> found that ets_class_from_arg() can index an Out-Of-Bound class in ets_class_from_arg() when passed clid of 0. The overflow may cause local privilege escalation. [ 18.852298] ------------[ cut here ]------------ [ 18.853271] UBSAN: array-index-out-of-bounds in net/sched/sch_ets.c:93:20 [ 18.853743] index 18446744073709551615 is out of range for type 'ets_class [16]' [ 18.854254] CPU: 0 UID: 0 PID: 1275 Comm: poc Not tainted 6.12.6-dirty #1

CVE-2025-31188
macOS General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to bypass Privacy preferences.

CVE-2025-54257
Acrobat Reader General
7.8
HIGH
EPSS
0.0%
2025 CWE-416 1 PoC

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.

CVE-2025-25178
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2025 CWE-1284 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.

CVE-2025-23105
Software Genérico General
7.8
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.

CVE-2025-24380
Unity General
7.8
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

CVE-2025-30456
iOS and iPadOS General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVE-2025-1079
Web Designer General
7.8
HIGH
EPSS
0.1%
2025 CWE-61 1 PoC

Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature

CVE-2025-24170
macOS General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVE-2025-62199
Microsoft 365 Apps for Enterprise General
7.8
HIGH
EPSS
0.5%
2025 CWE-416 2 PoCs

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-57392
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone and BUILTIN\Users groups FILE_ALL_ACCESS, allowing local users to replace or modify .exe and .dll files. This may lead to privilege escalation or arbitrary code execution upon launch by another user or elevated context.

CVE-2025-9329
PDF Reader General
7.8
HIGH
EPSS
0.1%
2025 CWE-125 1 PoC

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in

CVE-2025-10541
iMonitor EAM General
7.8
HIGH
EPSS
0.0%
2025 CWE-732 3 PoCs

iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files placed in the C:\sysupdate\ directory during startup. Because any local user can create and write to this directory, an attacker can place malicious DLLs or executables in it. Upon service restart, the files are moved to the application’s installation path and executed with SYSTEM privileges, leading to privilege escalation.