2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-34119
EasyCafe Server General
8.8
HIGH
EPSS
29.6%
2025 CWE-668 2 PoCs

A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. If the file exists and is accessible, its content is returned without authentication. This flaw allows attackers to retrieve sensitive files such as system configuration, password files, or application data.

CVE-2025-10201
Chrome General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVE-2025-23093
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges.

CVE-2025-21064
Smart Switch General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

CVE-2025-7657
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-45466
Software Genérico General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.

CVE-2025-1006
Chrome General
8.8
HIGH
EPSS
0.6%
2025 CWE-416 1 PoC

Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. (Chromium security severity: Medium)

CVE-2025-8109
Graphics DDK General
8.8
HIGH
EPSS
0.0%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory.

CVE-2025-28237
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.

CVE-2025-0434
Chrome General
8.8
HIGH
EPSS
0.4%
2025 1 PoC

Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-56101
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-56108
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

CVE-2025-12907
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-20 1 PoC

Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low)

CVE-2025-8663
upKeeper Manager General
8.8
HIGH
EPSS
0.1%
2025 CWE-532 1 PoC

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.0.0 before 5.2.12.

CVE-2025-12485
Server General
8.8
HIGH
EPSS
0.1%
2025 CWE-269 1 PoC

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through 2025.3.5.0 * Devolutions Server 2025.2.15.0 and earlier

CVE-2025-56111
Software Genérico General
8.8
HIGH
EPSS
1.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the network_set_wan_conf in file /usr/lib/lua/luci/controller/admin/netport.lua.

CVE-2025-60786
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 1 PoC

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip file.

CVE-2025-10500
Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-416 1 PoC

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-14766
Chrome General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-23102
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Double Free in the mobile processor leads to privilege escalation.