2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-4082
Firefox General
5.9
MEDIUM
EPSS
0.3%
2025 1 PoC

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10.

CVE-2025-43919
Mailman General
5.8
MEDIUM
EPSS
0.2%
2025 CWE-24 2 PoCs

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CVE-2025-26318
TSplus Remote Access General
5.8
MEDIUM
EPSS
1.7%
2025 CWE-201 1 PoC

hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.

CVE-2025-47872
EG4 12kPV General
5.8
MEDIUM
EPSS
0.1%
2025 CWE-203 1 PoC

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.

CVE-2025-21021
Blockchain Keystore General
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-55194
Part-DB-server General
5.7
MEDIUM
EPSS
0.0%
2025 CWE-248 1 PoC

Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.

CVE-2025-63226
Software Genérico General
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

CVE-2025-3886
SDP Client General
5.7
MEDIUM
EPSS
0.1%
2025 CWE-362 1 PoC

An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.

CVE-2025-1035
KLog Server General ⚡ nuclei
5.7
MEDIUM
EPSS
67.7%
2025 CWE-22 0 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.

CVE-2025-46710
Graphics DDK General
5.7
MEDIUM
EPSS
0.1%
2025 CWE-416 1 PoC

Possible kernel exceptions caused by reading and writing kernel heap data after free.

CVE-2025-21020
Blockchain Keystore General
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-21044
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-52294
Software Genérico General
5.7
MEDIUM
EPSS
0.1%
2025 1 PoC

Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view the wallet balance.

CVE-2025-32875
Software Genérico General
5.7
MEDIUM
EPSS
0.0%
2025 3 PoCs

An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any data transmitted via BLE remains unencrypted, allowing attackers within Bluetooth range to eavesdrop on the communication. Furthermore, even if a user manually initiates pairing and bonding in the Android settings, the application continues to transmit data without requiring the watch to be bonded. This fallback behavior enables attackers to exploit the commu

CVE-2025-14806
Planning Analytics Local General
5.7
MEDIUM
EPSS
0.0%
2025 CWE-524 1 PoC

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources.

CVE-2025-13821
Mattermost General
5.7
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560

CVE-2025-48172
CHMLib General
5.6
MEDIUM
EPSS
0.1%
2025 CWE-190 1 PoC

CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.

CVE-2025-1055
K7 Security Anti-Malware General
5.6
MEDIUM
EPSS
0.0%
2025 CWE-862 2 PoCs

A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating system. This flaw stems from missing access control in the driver's IOCTL handler, enabling unprivileged users to perform privileged actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical services or privileged applications.

CVE-2025-52993
Nix General
5.6
MEDIUM
EPSS
0.1%
2025 CWE-362 1 PoC

A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

CVE-2025-47256
Libxmp General
5.6
MEDIUM
EPSS
0.1%
2025 CWE-191 2 PoCs

Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.