2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-58409
Graphics DDK General
3.5
LOW
EPSS
0.0%
2025 CWE-119 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory.

CVE-2025-22445
Mattermost General
3.5
LOW
EPSS
0.2%
2025 CWE-754 1 PoC

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

CVE-2025-13758
Server General
3.5
LOW
EPSS
0.0%
2025 CWE-200 1 PoC

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

CVE-2025-49810
Mattermost General
3.5
LOW
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts

CVE-2025-30345
OpenSlides General
3.5
LOW
EPSS
0.2%
2025 CWE-116 1 PoC

An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most cases, HTML entities are encoded properly, but not when deleting chats or deleting messages in these chats. This potentially allows attackers to interfere with the layout of the rendered website, but it is unlikely that victims would click on deleted chats or deleted messages.

CVE-2025-0717
Social Slider Feed General
3.5
LOW
EPSS
0.1%
2025 1 PoC

To exploit the vulnerability, it is necessary:

CVE-2025-58084
Mattermost General
3.5
LOW
EPSS
0.1%
2025 CWE-1287 1 PoC

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.

CVE-2025-66823
Software Genérico General
3.5
LOW
EPSS
0.1%
2025 1 PoC

An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).

CVE-2025-47700
Mattermost General
3.5
LOW
EPSS
0.0%
2025 CWE-918 1 PoC

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions

CVE-2025-25983
Software Genérico General
3.4
LOW
EPSS
0.2%
2025 1 PoC

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.

CVE-2025-27889
Wing FTP Server General
3.4
LOW
EPSS
0.2%
2025 CWE-15 2 PoCs

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.

CVE-2025-9323
PDF Reader General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2025-23340
NVIDIA CUDA Toolkit General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability may lead to a partial denial of service.

CVE-2025-9327
PDF Reader General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with othe

CVE-2025-9324
PDF Reader General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2025-23339
NVIDIA CUDA Toolkit General
3.3
LOW
EPSS
0.0%
2025 CWE-121 1 PoC

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running cuobjdump.

CVE-2025-21022
Galaxy Wearable General
3.3
LOW
EPSS
0.0%
2025 1 PoC

Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.

CVE-2025-21024
Smart View General
3.3
LOW
EPSS
0.0%
2025 1 PoC

Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.

CVE-2025-23338
NVIDIA CUDA Toolkit General
3.3
LOW
EPSS
0.0%
2025 CWE-129 1 PoC

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write by running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.