2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-47906
os/exec General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

CVE-2025-26055
Software Genérico General
6.5
MEDIUM
EPSS
0.8%
2025 1 PoC

An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.

CVE-2025-9076
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

CVE-2025-49196
SICK Field Analytics General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-327 1 PoC

A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of other users or devices, affecting the confidentiality and integrity of the device.

CVE-2025-52168
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system.

CVE-2025-25468
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.

CVE-2025-41395
Mattermost General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-1287 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.

CVE-2025-2522
C300 PCNT02 General
6.5
MEDIUM
EPSS
0.3%
2025 CWE-226 1 PoC

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect system behavior. Honeywell also recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1.  The affected Experion PKS products are C300, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The E

CVE-2025-47222
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded in the application or not to the clientside.

CVE-2025-65407
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream.

CVE-2025-32815
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
27.6%
2025 0 PoCs

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

CVE-2025-48414
cPH2 / cPP2 charging stations General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-798 2 PoCs

There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during development and provides an additional attack surface.

CVE-2025-26784
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 2 PoCs

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

CVE-2025-65797
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).

CVE-2025-51627
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator.

CVE-2025-55622
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings. NOTE: this is disputed by the Supplier because it is intentional behavior to ensure a predictable user experience.

CVE-2025-35965
Mattermost General
6.5
MEDIUM
EPSS
0.3%
2025 CWE-770 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.

CVE-2025-10548
CleverControl employee monitoring software General
6.5
MEDIUM
EPSS
0.4%
2025 CWE-295 2 PoCs

The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installer downloads and executes external components using curl.exe --insecure, enabling a man-in-the-middle attacker to deliver malicious files that are executed with SYSTEM privileges. This can lead to full remote code execution with administrative rights. No patch is available as the vendor has been unresponsive. It is assumed that previous versions are also affected, but this is not confirmed.

CVE-2025-64086
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2025-12431
Chrome General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: High)