2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-23107
Software Genérico General
8.6
HIGH
EPSS
0.4%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

CVE-2025-54135
cursor General
8.6
HIGH
EPSS
0.1%
2025 CWE-78 2 PoCs

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive MCP files, such as the .cursor/mcp.json file don't already exist in the workspace, an attacker can chain a indirect prompt injection vulnerability to hijack the context to write to the settings file and trigger RCE on the victim without user approval. This is fixed in version 1.3.9.

CVE-2025-43994
Dell Storage Manager General
8.6
HIGH
EPSS
0.1%
2025 CWE-306 1 PoC

Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

CVE-2025-53418
COMMGR General
8.6
HIGH
EPSS
0.1%
2025 CWE-121 1 PoC

Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.

CVE-2025-34200
Print Virtual Appliance Host General
8.6
HIGH
EPSS
0.0%
2025 CWE-312 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the appliance with the network account credentials in clear-text inside /etc/issue, and the file is world-readable by default. An attacker with local shell access can read /etc/issue to obtain the network account username and password. Using the network account an attacker can change network parameters via the appliance interface, enabling local misconfiguration, network disruption or further escalation depending on deployment.

CVE-2025-4680
upKeeper Instant Privilege Access General
8.6
HIGH
EPSS
0.1%
2025 CWE-20 1 PoC

Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects upKeeper Instant Privilege Access: before 1.4.0.

CVE-2025-12816
node-forge General
8.6
HIGH
EPSS
0.1%
2025 2 PoCs

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

CVE-2025-7766
Provisioning Manager General
8.6
HIGH
EPSS
0.3%
2025 CWE-611 2 PoCs

Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.

CVE-2025-51087
Software Genérico General
8.6
HIGH
EPSS
0.4%
2025 1 PoC

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.

CVE-2025-9961
AX10 V1/V1.2/V2/V2.6/V3/V3.6 General
8.6
HIGH
EPSS
0.2%
2025 CWE-120 1 PoC

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.6: before 1.2.1; AX1500 V1/V1.20/V1.26/V1.60/V1.80/V2.60/V3.6: before 1.3.11.

CVE-2025-4681
upKeeper Instant Privilege Access General
8.6
HIGH
EPSS
0.1%
2025 CWE-269 1 PoC

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affects upKeeper Instant Privilege Access: before 1.4.0.

CVE-2025-7012
Cato Client General
8.6
HIGH
EPSS
0.1%
2025 CWE-59 1 PoC

An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.

CVE-2025-23103
Software Genérico General
8.6
HIGH
EPSS
0.4%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

CVE-2025-34322
Log Server General
8.6
HIGH
EPSS
0.4%
2025 CWE-78 1 PoC

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain user-controlled settings—including model selection and connection parameters—are read from the global configuration and concatenated into a shell command that is executed via shell_exec() without proper input handling or command-line argument sanitation. An authenticated user with access to the 'Global Settings' page can supply crafted values in these fields to inject additional shell commands, r

CVE-2025-2521
C300 PCNT02 General
8.6
HIGH
EPSS
1.2%
2025 CWE-119 1 PoC

The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to an Overread Buffers, which could result in improper index validation against buffer borders leading to remote code execution. Honeywell recommends updating to the most recent version of Honeywell Experion PKS: 520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1. The affected Experion PKS products are C300 PCNT02, C300 PCNT05, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The E

CVE-2025-32367
face recognition application General
8.6
HIGH
EPSS
0.3%
2025 CWE-425 1 PoC

The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure Direct Object Reference. NOTE: the number 4.0.8 was used for both the unpatched and patched versions.

CVE-2025-5459
Puppet Enterprise General
8.6
HIGH
EPSS
0.3%
2025 CWE-78 1 PoC

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0.

CVE-2025-11921
iStats General
8.5
HIGH
EPSS
0.1%
2025 CWE-732 1 PoC

iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.

CVE-2025-9968
Armoury Crate General
8.5
HIGH
EPSS
0.0%
2025 CWE-59 1 PoC

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, please refer to section 'Security Update for Armoury Crate App' in the ASUS Security Advisory.

CVE-2025-49619
Skyvern General
8.5
HIGH
EPSS
73.5%
2025 CWE-1336 3 PoCs

Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE).