9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-51532
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.

CVE-2025-1710
Endress+Hauser MEAC300-FNADE4 General
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-58410
Graphics DDK General
7.5
HIGH
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections for the buffer resource.

CVE-2025-66744
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
6.0%
2025 0 PoCs

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

CVE-2025-55634
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial of Service (DoS) via initiating a large number of simultaneous ffmpeg-based stream pushes.

CVE-2025-63208
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.

CVE-2025-48498
Comdb2 General
7.5
HIGH
EPSS
0.2%
2025 CWE-476 2 PoCs

A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when processing a number of fields used for coordination. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this vulnerability.

CVE-2025-27594
SICK DL100-2xxxxxxx General
7.5
HIGH
EPSS
0.1%
2025 CWE-319 1 PoC

The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a pass-the-hash attack.

CVE-2025-49182
SICK Media Server General
7.5
HIGH
EPSS
0.5%
2025 CWE-540 1 PoC

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.

CVE-2025-52931
Mattermost Confluence Plugin General
7.5
HIGH
EPSS
0.1%
2025 CWE-754 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.

CVE-2025-52512
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in out-of-bounds memory access, leading to a denial of service.

CVE-2025-70250
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.

CVE-2025-61106
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVE-2025-66959
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 1 PoC

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

CVE-2025-57430
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials.

CVE-2025-27580
BRICS General
7.5
HIGH
EPSS
0.6%
2025 CWE-335 1 PoC

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.

CVE-2025-58180
OctoPrint General
7.5
HIGH
EPSS
1.6%
2025 CWE-78 1 PoC

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution if said filename becomes included in a command defined in a system event handler and said event gets triggered. If no event handlers executing system commands with uploaded filenames as parameters have been configured, this vulnerability does not have an impact. The vulnerability is patched in version 1.11.3. As a work

CVE-2025-30471
iOS and iPadOS General
7.5
HIGH
EPSS
0.5%
2025 4 PoCs

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A remote user may be able to cause a denial-of-service.

CVE-2025-52364
Software Genérico General
7.5
HIGH
EPSS
0.4%
2025 1 PoC

Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows remote attackers to connect to the device s shell over the network, potentially without authentication if default or weak credentials are present

CVE-2025-32948
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's "inbox" endpoint. By abusing the "Create Activity" functionality, it is possible to create crafted playlists which will cause either denial of service or an attacker-controlled blind SSRF.