2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-34189
Print Virtual Appliance Host General
6.9
MEDIUM
EPSS
0.1%
2025 CWE-732 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local inter-process communication (IPC) mechanism. The software stores IPC request and response files inside /opt/PrinterInstallerClient/tmp with world-readable and world-writable permissions. Any local user can craft malicious request files that are processed by privileged daemons, leading to unauthorized actions being executed in other user sessions. This breaks user session isolation, potentially all

CVE-2025-34053
IP camera, DVR, and NVR devices General
6.9
MEDIUM
EPSS
0.4%
2025 CWE-290 2 PoCs

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.

CVE-2025-4288
FTP Server General
6.9
MEDIUM
EPSS
0.6%
2025 CWE-120 1 PoC

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RNFR Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-34451
proxychains-ng General
6.9
MEDIUM
EPSS
0.0%
2025 CWE-121 1 PoC

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the application may write beyond the bounds of fixed-size stack buffers, leading to memory corruption or crashes. This vulnerability may allow denial of service and, under certain conditions, could be leveraged for further exploitation depending on the execution environment and applied mitigat

CVE-2025-2955
A3000RU General
6.9
MEDIUM
EPSS
0.2%
2025 CWE-284 1 PoC

A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/ExportIbmsConfig.sh of the component IBMS Configuration File Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-15082
ZLT M30s General
6.9
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management Interface. Performing manipulation of the argument goformId results in information disclosure. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-5551
FTP Server General
6.9
MEDIUM
EPSS
0.5%
2025 CWE-120 1 PoC

A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. This affects an unknown part of the component SYSTEM Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0401
reggie General
6.9
MEDIUM
EPSS
0.2%
2025 CWE-22 1 PoC

A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the file src/main/java/com/itheima/reggie/controller/CommonController.java. The manipulation of the argument name leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4161
FTP Server General
6.9
MEDIUM
EPSS
0.5%
2025 CWE-120 1 PoC

A vulnerability classified as critical has been found in PCMan FTP Server up to 2.0.7. This affects an unknown part of the component VERBOSE Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-12843
waveterm General
6.9
MEDIUM
EPSS
0.0%
2025 CWE-94 1 PoC

Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.

CVE-2025-7961
KAP General
6.9
MEDIUM
EPSS
0.0%
2025 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This issue affects KAP: 3.6.0.

CVE-2025-5220
FTP Server General
6.9
MEDIUM
EPSS
0.5%
2025 CWE-120 1 PoC

A vulnerability was found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component GET Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-2177
libzvbi General
6.9
MEDIUM
EPSS
0.1%
2025 CWE-190 1 PoC

A vulnerability classified as critical was found in libzvbi up to 0.2.43. This vulnerability affects the function vbi_search_new of the file src/search.c. The manipulation of the argument pat_len leads to integer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The patch is identified as ca1672134b3e2962cd392212c73f44f8f4cb489f. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly p

CVE-2025-5074
FTP Server General
6.9
MEDIUM
EPSS
0.5%
2025 CWE-120 2 PoCs

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component PROMPT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-4162
FTP Server General
6.9
MEDIUM
EPSS
0.5%
2025 CWE-120 1 PoC

A vulnerability classified as critical was found in PCMan FTP Server up to 2.0.7. This vulnerability affects unknown code of the component ASCII Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-3845
WebServer General
6.9
MEDIUM
EPSS
0.4%
2025 CWE-120 1 PoC

A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulnerability is the function Buffer::HasWritten of the file code/buffer/buffer.cpp. The manipulation of the argument writePos_ leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-2173
libzvbi General
6.9
MEDIUM
EPSS
0.3%
2025 CWE-824 1 PoC

A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The manipulation of the argument src_length leads to uninitialized pointer. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The patch is identified as 8def647eea27f7fd7ad33ff79c2d6d3e39948dce. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted

CVE-2025-0223
Protected Folder General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-476 1 PoC

A vulnerability was found in IObit Protected Folder up to 13.6.0.5. It has been classified as problematic. Affected is the function 0x8001E000/0x8001E00C/0x8001E004/0x8001E010 in the library IURegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-8864
YugabyteDB Anywhere General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-532 1 PoC

Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs

CVE-2025-41705
QUINT4-UPS/24DC/24DC/5/EIP General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-523 1 PoC

An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.