2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-23338
NVIDIA CUDA Toolkit General
3.3
LOW
EPSS
0.0%
2025 CWE-129 1 PoC

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write by running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.

CVE-2025-20977
Samsung Notes General
3.3
LOW
EPSS
0.1%
2025 1 PoC

Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

CVE-2025-25618
Software Genérico General
3.3
LOW
EPSS
0.1%
2025 1 PoC

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.

CVE-2025-9325
PDF Reader General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2025-1398
Mattermost General
3.3
LOW
EPSS
0.0%
2025 CWE-426 1 PoC

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.

CVE-2025-13321
Mattermost General
3.3
LOW
EPSS
0.0%
2025 CWE-532 1 PoC

Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.

CVE-2025-27715
Mattermost General
3.3
LOW
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.

CVE-2025-21023
WcsExtension for Galaxy Watch General
3.3
LOW
EPSS
0.0%
2025 1 PoC

Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.

CVE-2025-0011
AMD Ryzen™ 8000 Series Desktop Processors General
3.3
LOW
EPSS
0.1%
2025 CWE-212 1 PoC

Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in loss of confidentiality.

CVE-2025-20895
Galaxy Store General
3.2
LOW
EPSS
0.0%
2025 1 PoC

Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.

CVE-2025-59437
ip General
3.2
LOW
EPSS
0.0%
2025 CWE-918 1 PoC

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415. NOTE: in current versions of several applications, connection attempts to the IP address 0 (interpreted as 0.0.0.0) are blocked with error messages such as net::ERR_ADDRESS_INVALID. However, in some situations that depend on both application version and operating system, connection attempts to 0 and 0.0.0.0 are considered connection attempts to 127.0.0.1 (and, for

CVE-2025-46415
Nix General
3.2
LOW
EPSS
0.1%
2025 CWE-367 1 PoC

A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

CVE-2025-59436
ip General
3.2
LOW
EPSS
0.0%
2025 CWE-918 1 PoC

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415.

CVE-2025-52992
Nix General
3.2
LOW
EPSS
0.1%
2025 CWE-732 1 PoC

The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

CVE-2025-52991
Nix General
3.2
LOW
EPSS
0.1%
2025 CWE-276 1 PoC

The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

CVE-2025-9084
Mattermost General
3.1
LOW
EPSS
0.0%
2025 CWE-601 1 PoC

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs

CVE-2025-13870
Mattermost General
3.1
LOW
EPSS
0.0%
2025 CWE-306 1 PoC

Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to

CVE-2025-62772
M6a General
3.1
LOW
EPSS
0.0%
2025 CWE-305 1 PoC

On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.

CVE-2025-24839
Mattermost General
3.1
LOW
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override property to a post via the Wrangler plugin, provided both the AI and Wrangler plugins are enabled.

CVE-2025-1412
Mattermost General
3.1
LOW
EPSS
0.2%
2025 CWE-384 1 PoC

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.