2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-32093
Mattermost General
4.7
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via improper permission validation.

CVE-2025-21063
Samsung Voice Recorder General
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.

CVE-2025-20884
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2025 1 PoC

Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.

CVE-2025-47827
🔥 KEV Software Genérico General
4.6
MEDIUM
EPSS
0.9%
2025 1 PoC

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

CVE-2025-48073
openexr General
4.6
MEDIUM
EPSS
0.1%
2025 CWE-476 1 PoC

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.

CVE-2025-69893
Software Genérico General
4.6
MEDIUM
EPSS
0.1%
2025 1 PoC

A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which induce non-constant time execution and specific branch patterns for word searching. An attacker with physical access during the initial setup phase can collect a single side-channel trace. By utilizing profiling-based Deep Learning Side-Channel Analysis (DL-SCA), the attacker can recover the mnemonic code and subsequently

CVE-2025-20966
Samsung Gallery General
4.6
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.

CVE-2025-20894
Samsung Email General
4.6
MEDIUM
EPSS
0.2%
2025 1 PoC

Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multiple user profiles.

CVE-2025-20924
Samsung Notes General
4.6
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across multiple user profiles.

CVE-2025-22383
Software Genérico General
4.6
MEDIUM
EPSS
0.3%
2025 CWE-79 1 PoC

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity input validation issue exists in the Commerce B2B application, affecting the Contact Us functionality. This allows visitors to send e-mail messages that could contain unfiltered HTML markup in specific scenarios.

CVE-2025-63433
Software Genérico General
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.

CVE-2025-27442
Zoom Workplace Apps General
4.6
MEDIUM
EPSS
0.4%
2025 CWE-79 1 PoC

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVE-2025-30439
iOS and iPadOS General
4.6
MEDIUM
EPSS
0.1%
2025 2 PoCs

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.

CVE-2025-36730
Windsurf General
4.6
MEDIUM
EPSS
0.0%
2025 CWE-1427 1 PoC

A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.

CVE-2025-27441
Zoom Workplace Apps General
4.6
MEDIUM
EPSS
0.4%
2025 CWE-79 1 PoC

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVE-2025-60914
Software Genérico General
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo endpoint.

CVE-2025-56689
Software Genérico General
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response. NOTE: this is disputed by the Supplier because, by design, the product successfully authenticates a client that possesses a cookie whose validity time interval includes the current time, and thus authentication after any type of "interception" is not a violation of the security mod

CVE-2025-20898
Samsung Members General
4.6
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles.

CVE-2025-63432
Software Genérico General
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.

CVE-2025-20883
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.