2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-24113
Safari General
4.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.

CVE-2025-8582
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-20 1 PoC

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-65796
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

CVE-2025-65799
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

CVE-2025-27581
BRICS General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-425 1 PoC

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.

CVE-2025-59687
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization.

CVE-2025-3227
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel.

CVE-2025-52923
aTrust General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-732 1 PoC

Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.

CVE-2025-29705
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.

CVE-2025-27455
Endress+Hauser MEAC300-FNADE4 General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others to take control of their computer while clicking on seemingly innocuous objects.

CVE-2025-8583
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-0476
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2025 CWE-1287 1 PoC

Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment

CVE-2025-13765
Server General
4.3
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

CVE-2025-4664
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2025-20033
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1287 1 PoC

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.

CVE-2025-24216
Safari General
4.3
MEDIUM
EPSS
0.1%
2025 3 PoCs

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2025-48025
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 2 PoCs

In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000, there is an improper access control vulnerability related to a log file.

CVE-2025-46708
Graphics DDK General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.

CVE-2025-13767
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.

CVE-2025-24618
ElementInvader Addons for Elementor General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-862 1 PoC

Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.3.1.