2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-5864
TDSEE App General
6.3
MEDIUM
EPSS
0.3%
2025 CWE-307 1 PoC

A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the component Password Reset Confirmation Code Handler. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.15 is able to address this issue. It is recommended to upgr

CVE-2025-0444
Chrome General
6.3
MEDIUM
EPSS
0.2%
2025 CWE-416 1 PoC

Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-14697
Sixun Shanghui Group Business Management System General
6.3
MEDIUM
EPSS
0.1%
2025 CWE-552 1 PoC

A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this issue is some unknown functionality of the file /ExportFiles/. The manipulation results in files or directories accessible. The attack may be launched remotely. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-21017
Blockchain Keystore General
6.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-20905
Samsung Mobile Devices General
6.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.

CVE-2025-7098
Internet Security Premium General
6.3
MEDIUM
EPSS
1.3%
2025 CWE-22 2 PoCs

A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the component File Name Handler. The manipulation of the argument name/folder leads to path traversal. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-34508
ZendTo General
6.3
MEDIUM
EPSS
0.9%
2025 CWE-22 1 PoC

A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host system, or cause a denial of service.

CVE-2025-6533
novel-plus General
6.3
MEDIUM
EPSS
0.4%
2025 CWE-294 2 PoCs

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA Handler. The manipulation leads to authentication bypass by capture-replay. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not

CVE-2025-50125
EcoStruxure™ IT Data Center Expert General
6.3
MEDIUM
EPSS
0.6%
2025 CWE-918 1 PoC

A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.

CVE-2025-55625
Software Genérico General
6.3
MEDIUM
EPSS
0.1%
2025 1 PoC

An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior that supports redirection to Alexa URLs, which are not guaranteed to remain at the same domain indefinitely.

CVE-2025-24212
iOS and iPadOS General
6.3
MEDIUM
EPSS
0.0%
2025 4 PoCs

This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.

CVE-2025-20910
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

CVE-2025-60419
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.

CVE-2025-20970
Bixby Vision General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege.

CVE-2025-20965
Voice wake-up General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.

CVE-2025-21059
Samsung Health General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

CVE-2025-54764
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.

CVE-2025-52516
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service.

CVE-2025-20997
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.

CVE-2025-21041
Secure Folder General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.