2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-58344
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation in a /proc/driver/unifi0/conn_log_event_burst_to_us write operation, leading to kernel memory exhaustion.

CVE-2025-11187
OpenSSL General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-787 1 PoC

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations. When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without vali

CVE-2025-0758
Pentaho Business Analytics Server General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-732 1 PoC

Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732)  Description  Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, is installed with Karaf JMX beans enabled and accessible by default.  Impact  When the vulnerability is leveraged, a user with local execution privileges can access functionality exposed by Karaf beans contained in the product.

CVE-2025-36173
InfoSphere Data Architect General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Affected Product(s)Version(s)InfoSphere Data Architect9.2.1

CVE-2025-52277
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field

CVE-2025-32970
xwiki-platform General ⚡ nuclei
6.1
MEDIUM
EPSS
0.1%
2025 CWE-601 0 PoCs

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirects to any URL. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0.

CVE-2025-14372
Chrome General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-416 1 PoC

Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-20974
PackageInstallerCN General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.

CVE-2025-45960
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding

CVE-2025-66880
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute arbitrary code via the LoginComp (Module 2093) and SignupComp (Module 2094) modules.

CVE-2025-46611
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.

CVE-2025-64736
libbiosig General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-125 2 PoCs

An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afb0). A specially crafted .abf file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-29094
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2025 1 PoC

Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components.

CVE-2025-65754
Software Genérico General
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.

CVE-2025-55035
Mattermost General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-754 1 PoC

Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a modal popup that cannot be closed.

CVE-2025-9862
Ghost General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

CVE-2025-45083
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspecified vectors.

CVE-2025-59480
Mattermost General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses

CVE-2025-26408
Wattsense Bridge General
6.1
MEDIUM
EPSS
0.2%
2025 CWE-1191 3 PoCs

The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.

CVE-2025-25615
Software Genérico General
6.0
MEDIUM
EPSS
0.4%
2025 1 PoC

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.