2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-52078
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint.

CVE-2025-67115
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to read arbitrary files from the filesystem via crafted values in the log_type parameter to /logsave.htm.

CVE-2025-43714
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers.

CVE-2025-51459
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hub._sanitize_filename and plugins_util.scan_plugins.

CVE-2025-55629
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allow attackers to arbitrarily change other users' passwords via manipulation of the userName value.

CVE-2025-57305
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

CVE-2025-10720
WP Private Content Plus General
6.5
MEDIUM
EPSS
0.2%
2025 2 PoCs

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

CVE-2025-45746
ZKBio CVSecurity General
6.5
MEDIUM
EPSS
0.9%
2025 CWE-321 1 PoC

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and because access to the service console does not result in login access or data access in the context of the application software platform.

CVE-2025-45663
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

CVE-2025-12808
Server General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-284 1 PoC

Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through 2025.3.5.0 * Devolutions Server 2025.2.15.0 and earlier

CVE-2025-9076
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

CVE-2025-25691
Software Genérico General
6.5
MEDIUM
EPSS
0.5%
2025 1 PoC

A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.

CVE-2025-5273
mcp-markdownify-server General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-552 1 PoC

All versions of the package mcp-markdownify-server are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.

CVE-2025-56748
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.

CVE-2025-30432
iOS and iPadOS General
6.4
MEDIUM
EPSS
0.1%
2025 4 PoCs

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.

CVE-2025-20983
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-54962
OpenPLC_v3 General
6.4
MEDIUM
EPSS
0.1%
2025 CWE-434 1 PoC

/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI.

CVE-2025-48731
Mattermost Confluence Plugin General
6.4
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint.

CVE-2025-52920
InnoShop General
6.4
MEDIUM
EPSS
0.2%
2025 CWE-425 1 PoC

Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their reviews of products on the website. To be specific, an attacker could view the order details of any order by browsing to /en/account/orders/_ORDER_ID_ or use the address and billing information of other customers by manipulating the shipping_address_id and billing_address_id parameters when making an order (this inform

CVE-2025-20885
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption.