2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-9867
Chrome General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-67282
Software Genérico General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.

CVE-2025-46702
Mattermost General
5.4
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via the playbook run participants feature, even when the 'Manage Members' permission has been explicitly removed. This can lead to unauthorized access to sensitive channel content and allow guest users to gain channel management privileg

CVE-2025-55177
🔥 KEV WhatsApp Desktop for Mac General
5.4
MEDIUM
EPSS
0.7%
2025 1 PoC

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

CVE-2025-46018
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss.

CVE-2025-55179
WhatsApp Business for iOS General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.

CVE-2025-24271
iOS and iPadOS General
5.4
MEDIUM
EPSS
0.3%
2025 1 PoC

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing.

CVE-2025-26056
Software Genérico General
5.4
MEDIUM
EPSS
0.6%
2025 1 PoC

A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.

CVE-2025-13097
Chrome General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-20973
Secure Folder General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type of Secure Folder.

CVE-2025-2475
Mattermost General
5.4
MEDIUM
EPSS
0.2%
2025 CWE-303 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.

CVE-2025-12908
Chrome General
5.4
MEDIUM
EPSS
0.1%
2025 CWE-20 1 PoC

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-65798
Software Genérico General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

CVE-2025-41410
Mattermost General
5.4
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import data to bypass email-based team access restrictions

CVE-2025-50817
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code. NOTE: Multiple third parties have disputed this issue and stated that it is not a security flaw in python-future and is a documented feature of Python’s import system in the handling of sys.path.

CVE-2025-5267
Firefox General
5.4
MEDIUM
EPSS
0.4%
2025 1 PoC

A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

CVE-2025-43920
Mailman General
5.4
MEDIUM
EPSS
1.4%
2025 CWE-78 1 PoC

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CVE-2025-11210
Chrome General
5.4
MEDIUM
EPSS
0.0%
2025 CWE-1300 1 PoC

Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-50477
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.

CVE-2025-13632
Chrome General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)