9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-48548
Android General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

CVE-2025-35036
Hibernate Validator General
7.3
HIGH
EPSS
1.7%
2025 CWE-94 1 PoC

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Lan

CVE-2025-20903
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

CVE-2025-20957
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.

CVE-2025-55618
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field in navigation app which then get rendered.

CVE-2025-60375
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 2 PoCs

The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without providing valid credentials.

CVE-2025-23094
Software Genérico General
7.3
HIGH
EPSS
2.1%
2025 1 PoC

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the same privilege level as the web access process.

CVE-2025-28026
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.

CVE-2025-3029
Firefox General
7.3
HIGH
EPSS
0.7%
2025 1 PoC

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was fixed in Firefox 137, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

CVE-2025-1550
Keras General
7.3
HIGH
EPSS
8.0%
2025 CWE-94 1 PoC

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.

CVE-2025-49144
notepad-plus-plus General
7.3
HIGH
EPSS
0.1%
2025 CWE-272 13 PoCs

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This is

CVE-2025-28020
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

CVE-2025-26125
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

CVE-2025-43947
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 1 PoC

Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.

CVE-2025-11446
upKeeper Manager General
7.3
HIGH
EPSS
0.0%
2025 CWE-532 1 PoC

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 before 5.2.12.

CVE-2025-58320
DIALink General
7.3
HIGH
EPSS
0.1%
2025 CWE-22 1 PoC

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

CVE-2025-22417
Android General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2025-3197
expand-object General
7.3
HIGH
EPSS
0.6%
2025 CWE-1321 1 PoC

Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like __proto__.

CVE-2025-22386
Software Genérico General
7.3
HIGH
EPSS
0.2%
2025 CWE-613 1 PoC

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.

CVE-2025-52490
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.