2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-6299
N150RT General
5.1
MEDIUM
EPSS
5.9%
2025 CWE-78 1 PoC

A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-11655
Flow General
5.1
MEDIUM
EPSS
0.0%
2025 CWE-434 1 PoC

A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-20951
Galaxy Store General
5.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.

CVE-2025-9145
Scada-LTS General
5.1
MEDIUM
EPSS
0.0%
2025 CWE-79 2 PoCs

A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file view_edit.shtm of the component SVG File Handler. Such manipulation of the argument backgroundImageMP leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2025-59933
libvips General
5.1
MEDIUM
EPSS
0.0%
2025 CWE-126 2 PoCs

libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips is compiled with support for PDF input via poppler, the pdfload operation is affected by a buffer read overflow when parsing the header of a crafted PDF with a page that defines a width but not a height. Those using libvips compiled without support for PDF input are unaffected as well as thosewith support for PDF input via PDFium. This issue is fixed in version 8.17.2. A workaround for those affected is to block the VipsForeignLoadPdf operation via vips_operation_block_set, w

CVE-2025-3219
Perfex CRM General
5.1
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown function of the file /perfex/clients/project/2 of the component Project Discussions Module. The manipulation of the argument description leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-15112
lares General
5.1
MEDIUM
EPSS
0.0%
2025 CWE-601 1 PoC

Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.

CVE-2025-9407
mblog General
5.1
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing manipulation of the argument signature can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Other parameters might be affected as well.

CVE-2025-9143
Scada-LTS General
5.1
MEDIUM
EPSS
0.0%
2025 CWE-79 2 PoCs

A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. The manipulation of the argument name/userList/address results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.

CVE-2025-1392
DIR-816 General
5.1
MEDIUM
EPSS
1.8%
2025 CWE-79 2 PoCs

A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. The manipulation of the argument SSID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2025-11345
ILIAS General
5.1
MEDIUM
EPSS
0.1%
2025 CWE-502 1 PoC

A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 can resolve this issue. Upgrading the affected component is advised.

CVE-2025-9106
i-Diario General
5.1
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-0287
Migrate OS to SSD General
5.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

CVE-2025-20893
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.

CVE-2025-59109
dormakaba registration unit 9002 General
5.1
MEDIUM
EPSS
0.0%
2025 CWE-1295 2 PoCs

The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sending every button press to the UART interface. An attacker can use the interface to exfiltrate PINs. As the devices are explicitly built as Plug-and-Play to be easily replaced, an attacker is easily able to remove the device, install a hardware implant which connects to the UART and exfiltrates the data exposed via UART to another system (e.g. via WiFi).

CVE-2025-0691
Server General
5.0
MEDIUM
EPSS
0.2%
2025 CWE-284 1 PoC

Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.

CVE-2025-24203
iOS and iPadOS General
5.0
MEDIUM
EPSS
0.0%
2025 3 PoCs

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to modify protected parts of the file system.

CVE-2025-24097
iOS and iPadOS General
5.0
MEDIUM
EPSS
0.0%
2025 2 PoCs

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to read arbitrary file metadata.

CVE-2025-48461
Advantech Wireless Sensing and Equipment (WISE) General
5.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

CVE-2025-47226
Snipe-IT General
5.0
MEDIUM
EPSS
1.0%
2025 CWE-425 2 PoCs

Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.