2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-47226
Snipe-IT General
5.0
MEDIUM
EPSS
1.0%
2025 CWE-425 2 PoCs

Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

CVE-2025-21036
Samsung Notes General
5.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported note files. User interaction is required for triggering this vulnerability.

CVE-2025-60251
Go2 General
5.0
MEDIUM
EPSS
0.0%
2025 CWE-306 1 PoC

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.

CVE-2025-32102
CrushFTP General
5.0
MEDIUM
EPSS
0.5%
2025 CWE-918 2 PoCs

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.

CVE-2025-69620
Software Genérico General
5.0
MEDIUM
EPSS
0.0%
2025 1 PoC

A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.

CVE-2025-20996
Smart Switch General
5.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability.

CVE-2025-51475
Software Genérico General
5.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().

CVE-2025-54458
Mattermost Confluence Plugin General
5.0
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.

CVE-2025-68463
Biopython General
4.9
MEDIUM
EPSS
0.1%
2025 CWE-611 1 PoC

Bio.Entrez in Biopython through 186 allows doctype XXE.

CVE-2025-24911
Pentaho Business Analytics Server General
4.9
MEDIUM
EPSS
0.2%
2025 CWE-611 2 PoCs

Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is processing the XML. This application may echo back the data (e.g. in an error message), thereby exposing the file contents. (CWE-611)   Description   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.2, including 9.3.x and 8.3.x, do not

CVE-2025-20995
Samsung Internet General
4.9
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files.

CVE-2025-8402
Mattermost General
4.9
MEDIUM
EPSS
0.1%
2025 CWE-1287 1 PoC

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.

CVE-2025-49015
Software Genérico General
4.9
MEDIUM
EPSS
0.2%
2025 2 PoCs

The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.

CVE-2025-24910
Pentaho Business Analytics Server General
4.9
MEDIUM
EPSS
0.2%
2025 CWE-611 2 PoCs

Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is processing the XML. This application may echo back the data (e.g. in an error message), thereby exposing the file contents. (CWE-611)   Description   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.2, including 9.3.x and 8.3.x, do not

CVE-2025-41676
mbNET.mini General
4.9
MEDIUM
EPSS
0.2%
2025 CWE-400 1 PoC

A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession.

CVE-2025-41677
mbNET.mini General
4.9
MEDIUM
EPSS
0.2%
2025 CWE-400 1 PoC

A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession.

CVE-2025-9394
PoDoFo General
4.8
MEDIUM
EPSS
0.0%
2025 CWE-416 1 PoC

A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/podofo/main/PdfTokenizer.cpp of the component PDF Dictionary Parser. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been published and may be used. This patch is called 22d16cb142f293bf956f66a4d399cdd65576d36c. A patch should be applied to remediate this issue.

CVE-2025-8066
Bunker Web General
4.8
MEDIUM
EPSS
0.1%
2025 CWE-601 1 PoC

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This issue affects Bunker Web: 1.6.2.

CVE-2025-8732
libxml2 General
4.8
MEDIUM
EPSS
0.0%
2025 CWE-674 1 PoC

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGM

CVE-2025-9103
ZenCart General
4.8
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor declares this as "intended behavior, allowed for authorized administrators".