9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-21006
libsavsvc.so General
7.0
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.

CVE-2025-11001
7-Zip General
7.0
HIGH
EPSS
0.3%
2025 CWE-22 1 PoC

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26753.

CVE-2025-20882
Samsung Mobile Devices General
7.0
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

CVE-2025-24209
Safari General
7.0
HIGH
EPSS
0.6%
2025 2 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2025-28128
Software Genérico General
7.0
HIGH
EPSS
0.3%
2025 1 PoC

An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

CVE-2025-34324
GoSign Desktop General
7.0
HIGH
EPSS
0.0%
2025 CWE-347 2 PoCs

GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The manifest contains package URLs and SHA-256 hashes but is not digitally signed, so its authenticity relies solely on the underlying TLS channel. In affected versions, TLS certificate validation can be disabled when a proxy is configured, allowing an attacker who can intercept network traffic to supply a malicious update manifest and corresponding package with a matching hash. This can cause the client to download and install a tampered update, resulting in arbitrary code execution

CVE-2025-34503
Deck Mate 1 General
7.0
HIGH
EPSS
0.0%
2025 CWE-347 1 PoC

Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates modern secure-boot or signed-update mechanisms, affected systems should be physically protected or retired from service. The vendor has not indicated that firmware updates are available for this legacy model.

CVE-2025-0411
🔥 KEV 7-Zip General
7.0
HIGH
EPSS
52.4%
2025 CWE-693 10 PoCs

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the contex

CVE-2025-20890
Samsung Mobile Devices General
7.0
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

CVE-2025-59104
Access Manager 92xx-k7 General
7.0
HIGH
EPSS
0.0%
2025 CWE-1234 2 PoCs

With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or use the 6-Pin tag-connect cable). Thus, the attacker gains access to the bootloader, where the kernel command line can be changed. An attacker is able to gain a root shell through this vulnerability.

CVE-2025-34500
Deck Mate 2 General
7.0
HIGH
EPSS
0.0%
2025 CWE-321 3 PoCs

Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with access to the update interface - typically via the unit's USB update port - can craft or modify firmware packages to execute arbitrary code as root, allowing persistent compromise of the device's integrity and deck randomization process. Physical or on-premises access remains the most likely attack path, though network-exposed or telemetry-enabled deployment

CVE-2025-67896
Exim General
7.0
HIGH
EPSS
0.1%
2025 CWE-122 1 PoC

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

CVE-2025-4653
Pandora ITSM General
7.0
HIGH
EPSS
63.9%
2025 CWE-77 1 PoC

Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

CVE-2025-8862
YugabyteDB General
7.0
HIGH
EPSS
0.1%
2025 CWE-201 1 PoC

YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

CVE-2025-11901
B460 series General
7.0
HIGH
EPSS
0.0%
2025 CWE-284 1 PoC

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.

CVE-2025-6019
Software Genérico General
7.0
HIGH
EPSS
0.0%
2025 CWE-250 8 PoCs

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, th

CVE-2025-34502
Deck Mate 2 General
7.0
HIGH
EPSS
0.0%
2025 CWE-1326 1 PoC

Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. Without cryptographic boot verification, an attacker with physical access can modify or replace the bootloader, kernel, or filesystem and gain persistent code execution on reboot. This weakness allows long-term firmware tampering that survives power cycles. The vendor indicates that more recent firmware updates strengthen update-chain integrity and disable physical update ports to mitigate related attack avenues.

CVE-2025-5306
Pandora FMS General
7.0
HIGH
EPSS
71.3%
2025 CWE-77 1 PoC

Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778

CVE-2025-4678
Pandora ITSM General
7.0
HIGH
EPSS
1.2%
2025 CWE-77 1 PoC

Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

CVE-2025-20881
Samsung Mobile Devices General
7.0
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.