9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-49494
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 5123. Mishandling of an 5G NRMM packet leads to a Denial of Service.

CVE-2025-46709
Graphics DDK General
7.5
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kernel exception.

CVE-2025-67015
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

CVE-2025-65857
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

CVE-2025-3194
bigint-buffer General
7.5
HIGH
EPSS
0.4%
2025 CWE-120 1 PoC

Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.

CVE-2025-12758
validator General
7.5
HIGH
EPSS
0.1%
2025 CWE-792 2 PoCs

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.

CVE-2025-29448
Software Genérico General
7.5
HIGH
EPSS
0.5%
2025 1 PoC

Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.

CVE-2025-41703
QUINT4-UPS/24DC/24DC/5/EIP General
7.5
HIGH
EPSS
0.2%
2025 CWE-306 1 PoC

An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command.

CVE-2025-56223
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.

CVE-2025-61107
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.

CVE-2025-25382
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

CVE-2025-37097
Insight Remote Support General
7.5
HIGH
EPSS
0.5%
2025 1 PoC

A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service

CVE-2025-70243
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.

CVE-2025-26780
Software Genérico General
7.5
HIGH
EPSS
0.5%
2025 2 PoCs

An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Service via a malformed PDCP packet.

CVE-2025-9784
Software Genérico General
7.5
HIGH
EPSS
1.7%
2025 CWE-770 1 PoC

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CVE-2025-12430
Chrome General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

CVE-2025-2264
Sante PACS Server General ⚡ nuclei
7.5
HIGH
EPSS
64.4%
2025 CWE-22 1 PoC

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

CVE-2025-32470
SICK FLX0-GPNT100 General
7.5
HIGH
EPSS
0.7%
2025 CWE-284 1 PoC

A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.

CVE-2025-9146
E5600 General
7.5
HIGH
EPSS
0.3%
2025 CWE-327 1 PoC

A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-60349
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver. Any processes listed under registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxscan\Files will be terminated.