2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-55623
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using an ADB (Android Debug Bridge).

CVE-2025-55073
Mattermost General
5.4
MEDIUM
EPSS
0.0%
2025 CWE-306 1 PoC

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.

CVE-2025-67280
Software Genérico General
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and access sensitive data of another user.

CVE-2025-9382
Y215 CCTV Camera General
5.4
MEDIUM
EPSS
0.0%
2025 CWE-912 2 PoCs

A weakness has been identified in FNKvision Y215 CCTV Camera 10.194.120.40. This vulnerability affects unknown code of the file s1_rf_test_config of the component Telnet Sevice. Executing manipulation can lead to backdoor. The physical device can be targeted for the attack. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-29632
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2025 2 PoCs

Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components

CVE-2025-27933
Mattermost General
5.4
MEDIUM
EPSS
0.3%
2025 CWE-863 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public

CVE-2025-44109
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

CVE-2025-0445
Chrome General
5.4
MEDIUM
EPSS
0.0%
2025 CWE-416 1 PoC

Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-20939
Samsung Mobile Devices General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices.

CVE-2025-12916
Operation and Maintenance Security Management System General
5.3
MEDIUM
EPSS
0.2%
2025 CWE-77 1 PoC

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This manipulation of the argument loginUrl causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.0.11 and 3.0.12 is recommended to address this issue. It is advisable to upgrade the affected component.

CVE-2025-51533
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.

CVE-2025-30344
OpenSlides General
5.3
MEDIUM
EPSS
0.2%
2025 CWE-208 1 PoC

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

CVE-2025-58583
Enterprise Analytics General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-497 1 PoC

The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

CVE-2025-43921
Mailman General
5.3
MEDIUM
EPSS
0.4%
2025 CWE-863 1 PoC

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CVE-2025-3562
YonBIP General
5.3
MEDIUM
EPSS
0.3%
2025 CWE-22 2 PoCs

A vulnerability was found in Yonyou YonBIP MA2.7. It has been declared as problematic. Affected by this vulnerability is the function FileInputStream of the file /mobsm/common/userfile. The manipulation of the argument path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-49188
SICK Field Analytics General
5.3
MEDIUM
EPSS
0.4%
2025 CWE-598 1 PoC

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

CVE-2025-5442
RE6500 General
5.3
MEDIUM
EPSS
5.7%
2025 CWE-78 1 PoC

A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_pingGatewayByBBS of the file /goform/RP_pingGatewayByBBS. The manipulation of the argument ip/nm/gw leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-49186
Field Analytics General
5.3
MEDIUM
EPSS
0.3%
2025 CWE-307 1 PoC

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-20891
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

CVE-2025-10674
platform General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-285 2 PoCs

A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController of the file /attributecategory/queryAll. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used.