2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-25616
Software Genérico General
7.6
HIGH
EPSS
0.6%
2025 1 PoC

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.

CVE-2025-1933
Firefox General
7.6
HIGH
EPSS
0.5%
2025 1 PoC

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-9959
Software Genérico General
7.6
HIGH
EPSS
0.1%
2025 CWE-94 1 PoC

Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.

CVE-2025-23369
Enterprise Server General
7.6
HIGH
EPSS
11.8%
2025 CWE-347 2 PoCs

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML single sign-on or where the attacker is not already an existing user were not impacted. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12.14, 3.13.10, 3.14.7, 3.15.2, and 3.16.0. This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2025-30072
Software Genérico General
7.6
HIGH
EPSS
0.2%
2025 2 PoCs

Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.

CVE-2025-57430
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials.

CVE-2025-9146
E5600 General
7.5
HIGH
EPSS
0.3%
2025 CWE-327 1 PoC

A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-67133
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component

CVE-2025-8021
files-bucket-server General
7.5
HIGH
EPSS
0.7%
2025 CWE-22 1 PoC

All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files outside of the intended directory.

CVE-2025-70245
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.

CVE-2025-63800
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.

CVE-2025-65637
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVE-2025-63219
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.

CVE-2025-25475
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.

CVE-2025-1710
Endress+Hauser MEAC300-FNADE4 General
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-13654
Duc General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a condition can evaluate to true due to underflow, allowing an out-of-bounds read.

CVE-2025-32978
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 3 PoCs

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses through a web interface intended for license renewal. Attackers can exploit this to replace valid licenses with expired or trial licenses, causing denial of service.

CVE-2025-27580
BRICS General
7.5
HIGH
EPSS
0.6%
2025 CWE-335 1 PoC

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.

CVE-2025-58410
Graphics DDK General
7.5
HIGH
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections for the buffer resource.

CVE-2025-51868
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.