2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-30427
Safari General
4.3
MEDIUM
EPSS
0.2%
2025 3 PoCs

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2025-54320
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.

CVE-2025-21014
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-24526
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it

CVE-2025-21055
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

CVE-2025-47813
🔥 KEV Wing FTP Server General ⚡ nuclei
4.3
MEDIUM
EPSS
25.0%
2025 CWE-209 2 PoCs

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CVE-2025-49192
SICK Field Analytics General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while clicking on seemingly innocuous objects.

CVE-2025-9078
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2025 CWE-328 1 PoC

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to properly validate cache keys for link metadata which allows authenticated users to access unauthorized posts and poison link previews via hash collision attacks on FNV-1 hashing

CVE-2025-1922
Chrome General
4.3
MEDIUM
EPSS
0.3%
2025 CWE-451 1 PoC

Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-36599
PowerFlex Manager VM General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-532 1 PoC

Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.

CVE-2025-8577
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-21030
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.

CVE-2025-20956
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.

CVE-2025-59463
TLOC100-100 all Firmware versions General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-833 1 PoC

An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.

CVE-2025-1923
Chrome General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

CVE-2025-9914
Baggage Analytics General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-288 1 PoC

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.

CVE-2025-50340
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized to use the specified sender identity, resulting in unauthorized message delivery as another user. This can lead to impersonation, phishing, or unauthorized communication within the system. NOTE: this is disputed by the Supplier because the only effective way to prevent this sender

CVE-2025-12443
Chrome General
4.3
MEDIUM
EPSS
0.0%
2025 CWE-125 1 PoC

Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-9479
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-125 1 PoC

Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-25274
Mattermost General
4.3
MEDIUM
EPSS
0.5%
2025 CWE-863 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.