2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-25478
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.

CVE-2025-9076
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

CVE-2025-56499
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

CVE-2025-28371
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.

CVE-2025-57822
next.js General ⚡ nuclei
6.5
MEDIUM
EPSS
6.5%
2025 CWE-918 0 PoCs

Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in Next.js versions 14.2.32 and 15.4.7. All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the next() function.

CVE-2025-52493
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. This vulnerability is exploitable by administrative users who have access to the configuration page.

CVE-2025-46203
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.

CVE-2025-24949
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

In JotUrl 2.0, is possible to bypass security requirements during the password change process.

CVE-2025-65405
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file.

CVE-2025-54249
Adobe Experience Manager General ⚡ nuclei
6.5
MEDIUM
EPSS
6.3%
2025 CWE-918 0 PoCs

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass security controls allowing unauthorized read access.

CVE-2025-1704
ChromeOS General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.

CVE-2025-49200
SICK Field Analytics General
6.5
MEDIUM
EPSS
0.3%
2025 CWE-200 1 PoC

The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.

CVE-2025-59462
TLOC100-100 all Firmware versions General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-248 1 PoC

An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.

CVE-2025-8881
Chrome General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-56799
Software Genérico General
6.5
MEDIUM
EPSS
2.5%
2025 1 PoC

Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.

CVE-2025-12431
Chrome General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: High)

CVE-2025-22377
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol implementation because of a mismatch between the actual length of the payload and the length declared within the payload.

CVE-2025-23101
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privilege escalation.

CVE-2025-56503
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the uninstall file with a crafted binary in the installation folder. NOTE: this is disputed by the Supplier because replacing the uninstall file requires administrator permissions, i.e., there is no privilege escalation.

CVE-2025-6226
Mattermost General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts.