2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-4096
Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-122 1 PoC

Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-52930
SAIL Image Decoding Library General
8.8
HIGH
EPSS
0.4%
2025 CWE-680 2 PoCs

A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially crafted .bmp file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

CVE-2025-51865
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

CVE-2025-59106
Access Manager 92xx-k7 General
8.8
HIGH
EPSS
0.1%
2025 CWE-272 2 PoCs

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

CVE-2025-59684
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.

CVE-2025-9866
Chrome General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-46068
Software Genérico General
8.8
HIGH
EPSS
0.4%
2025 1 PoC

An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism

CVE-2025-1568
ChromeOS General
8.8
HIGH
EPSS
0.8%
2025 1 PoC

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.

CVE-2025-48543
🔥 KEV Android General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-56129
Software Genérico General
8.8
HIGH
EPSS
1.4%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnosis in file /usr/lib/lua/luci/controller/admin/diagnosis.lua.

CVE-2025-45081
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 1 PoC

Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.

CVE-2025-56092
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 2 PoCs

OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-13226
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-56123
Software Genérico General
8.8
HIGH
EPSS
0.9%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-50129
SAIL Image Decoding Library General
8.8
HIGH
EPSS
0.4%
2025 CWE-122 2 PoCs

A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a specially crafted .tga file, a heap-based buffer overflow can occur which allows for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

CVE-2025-14174
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.4%
2025 1 PoC

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2025-63434
Software Genérico General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.

CVE-2025-56098
Software Genérico General
8.8
HIGH
EPSS
0.6%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-10585
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.7%
2025 CWE-843 3 PoCs

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-56101
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.