2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-65797
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).

CVE-2025-26055
Software Genérico General
6.5
MEDIUM
EPSS
0.8%
2025 1 PoC

An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.

CVE-2025-51627
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator.

CVE-2025-55622
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings. NOTE: this is disputed by the Supplier because it is intentional behavior to ensure a predictable user experience.

CVE-2025-10548
CleverControl employee monitoring software General
6.5
MEDIUM
EPSS
0.4%
2025 CWE-295 2 PoCs

The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installer downloads and executes external components using curl.exe --insecure, enabling a man-in-the-middle attacker to deliver malicious files that are executed with SYSTEM privileges. This can lead to full remote code execution with administrative rights. No patch is available as the vendor has been unresponsive. It is assumed that previous versions are also affected, but this is not confirmed.

CVE-2025-64086
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2025-20908
Samsung Mobile Devices General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.

CVE-2025-49197
SICK Media Server General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-328 1 PoC

The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.

CVE-2025-31258
macOS General
6.5
MEDIUM
EPSS
0.1%
2025 3 PoCs

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.

CVE-2025-52493
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. This vulnerability is exploitable by administrative users who have access to the configuration page.

CVE-2025-65405
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file.

CVE-2025-20621
Mattermost General
6.5
MEDIUM
EPSS
0.4%
2025 CWE-1287 1 PoC

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel.

CVE-2025-20036
Mattermost General
6.5
MEDIUM
EPSS
0.4%
2025 CWE-1287 1 PoC

Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

CVE-2025-9076
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

CVE-2025-43720
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.

CVE-2025-0442
Chrome General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-51867
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM using other users' credits via sensitive information gained by the /browse/stories endpoint.

CVE-2025-67835
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality.

CVE-2025-2820
Product family GLx and CWx General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-400 1 PoC

An authenticated attacker can compromise the availability of the device via the network

CVE-2025-50420
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).