2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-55164
content-security-policy-parser General
8.8
HIGH
EPSS
0.2%
2025 CWE-1321 1 PoC

content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This issue has been patched in version 0.6.0. A workaround involves disabling prototype method in NodeJS, neutralizing all possible prototype pollution attacks. Provide either --disable-proto=delete (recommended) or --disable-proto=throw as an argument to node to enable this feature.

CVE-2025-9132
Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-1918
Chrome General
8.8
HIGH
EPSS
0.7%
2025 CWE-125 1 PoC

Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Medium)

CVE-2025-2073
ChromeOS General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure

CVE-2025-56087
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_tcpdump in file /usr/lib/lua/luci/controller/admin/common_tcpdump.lua.

CVE-2025-56084
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVE-2025-5958
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-0436
Chrome General
8.8
HIGH
EPSS
0.5%
2025 CWE-472 1 PoC

Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-53558
ZXHN-F660T General ⚡ nuclei
8.8
HIGH
EPSS
13.1%
2025 CWE-1391 0 PoCs

ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.

CVE-2025-10639
WorkExaminer Professional General
8.8
HIGH
EPSS
0.3%
2025 CWE-798 2 PoCs

The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain remote code execution as NT Authority\SYSTEM on the server by exchanging accessible service binaries in the WorkExaminer installation directory (e.g. "C:\Program File (x86)\Work Examiner Professional Server").

CVE-2025-3067
Chrome General
8.8
HIGH
EPSS
0.2%
2025 1 PoC

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted app. (Chromium security severity: Medium)

CVE-2025-12907
Chrome General
8.8
HIGH
EPSS
0.1%
2025 CWE-20 1 PoC

Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low)

CVE-2025-52456
SAIL Image Decoding Library General
8.8
HIGH
EPSS
0.4%
2025 CWE-680 2 PoCs

A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .webp animation an integer overflow can be made to occur when calculating the stride for decoding. Afterwards, this will cause a heap-based buffer to overflow when decoding the image which can lead to remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

CVE-2025-32061
Infotainment system ECU General
8.8
HIGH
EPSS
0.0%
2025 CWE-121 2 PoCs

The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper layer L2CAP channel. An attacker can leverage this vulnerability to obtain remote code execution on the Infotainment ECU with root privileges. First identified on Nissan Leaf ZE1 manufactured in 2020.

CVE-2025-56107
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config.lua.

CVE-2025-28237
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.

CVE-2025-53772
Web Deploy 4.0 General
8.8
HIGH
EPSS
11.1%
2025 CWE-502 3 PoCs

Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

CVE-2025-28030
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function.

CVE-2025-5063
Chrome General
8.8
HIGH
EPSS
0.5%
2025 CWE-416 1 PoC

Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-27683
Software Genérico General
8.8
HIGH
EPSS
0.4%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type V-2022-006.