2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-25758
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

CVE-2025-24221
iOS and iPadOS General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensitive keychain data may be accessible from an iOS backup.

CVE-2025-44652
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.

CVE-2025-61105
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVE-2025-54326
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in the Camera device driver can lead to a NULL pointer dereference, resulting in a denial of service.

CVE-2025-63205
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. NOTE: the Supplier disagrees that 6.5.0-9 is affected, and instead reports that 5.6.0-3 and earlier are affected, and 5.6.0-4 (2020-09-21) and later are fixed.

CVE-2025-27449
Endress+Hauser MEAC300-FNADE4 General
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-22384
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 CWE-472 1 PoC

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.

CVE-2025-65513
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources.

CVE-2025-49182
SICK Media Server General
7.5
HIGH
EPSS
0.5%
2025 CWE-540 1 PoC

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.

CVE-2025-25951
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

CVE-2025-27685
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.

CVE-2025-30567
WP01 General ⚡ nuclei
7.5
HIGH
EPSS
45.7%
2025 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Path Traversal.This issue affects WP01: from n/a through <= 2.6.2.

CVE-2025-61100
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.

CVE-2025-52931
Mattermost Confluence Plugin General
7.5
HIGH
EPSS
0.1%
2025 CWE-754 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.

CVE-2025-59375
libexpat General
7.5
HIGH
EPSS
0.1%
2025 CWE-770 1 PoC

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

CVE-2025-32470
SICK FLX0-GPNT100 General
7.5
HIGH
EPSS
0.7%
2025 CWE-284 1 PoC

A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.

CVE-2025-49494
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 5123. Mishandling of an 5G NRMM packet leads to a Denial of Service.

CVE-2025-61101
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVE-2025-63757
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.