2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-62690
Mattermost General
3.1
LOW
EPSS
0.1%
2025 CWE-601 1 PoC

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.

CVE-2025-9081
Mattermost General
3.1
LOW
EPSS
0.0%
2025 CWE-639 1 PoC

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration

CVE-2025-41436
Mattermost General
3.1
LOW
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

CVE-2025-62774
M6a General
3.1
LOW
EPSS
0.0%
2025 CWE-331 1 PoC

On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.

CVE-2025-0503
Mattermost General
3.1
LOW
EPSS
0.4%
2025 CWE-754 1 PoC

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.

CVE-2025-2424
Mattermost General
3.1
LOW
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.

CVE-2025-49198
SICK Media Server General
3.1
LOW
EPSS
0.3%
2025 CWE-330 1 PoC

The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.

CVE-2025-55074
Mattermost General
3.0
LOW
EPSS
0.0%
2025 CWE-1426 1 PoC

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

CVE-2025-31363
Mattermost General
3.0
LOW
EPSS
0.2%
2025 CWE-1426 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.

CVE-2025-13352
Mattermost General
3.0
LOW
EPSS
0.1%
2025 CWE-1287 1 PoC

Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.

CVE-2025-30343
OpenSlides General
3.0
LOW
EPSS
0.5%
2025 CWE-24 1 PoC

A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the title of a file or folder as a relative or absolute path (e.g., ../../../etc/passwd), the ZIP archive generated for download converts that title into a path. Depending on the extraction tool used by the user, this might overwrite files locally outside of the chosen directory.

CVE-2025-43718
Poppler General
2.9
LOW
EPSS
0.0%
2025 CWE-674 1 PoC

Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::__detail::_Executor).

CVE-2025-50422
Cairo General
2.9
LOW
EPSS
0.0%
2025 CWE-617 1 PoC

Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

CVE-2025-47816
PSPP General
2.9
LOW
EPSS
0.2%
2025 CWE-125 1 PoC

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.

CVE-2025-46416
Nix General
2.9
LOW
EPSS
0.1%
2025 CWE-282 1 PoC

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

CVE-2025-47229
PSPP General
2.9
LOW
EPSS
0.0%
2025 CWE-617 1 PoC

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code.

CVE-2025-48188
PSPP General
2.9
LOW
EPSS
0.1%
2025 CWE-125 1 PoC

libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.

CVE-2025-65185
Software Genérico General
2.8
LOW
EPSS
0.0%
2025 1 PoC

There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses.