2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-3558
uzy-ssm-mall General
5.3
MEDIUM
EPSS
0.3%
2025 CWE-434 1 PoC

A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uploadUserHeadImage. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-54331
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.

CVE-2025-27218
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
76.1%
2025 0 PoCs

Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

CVE-2025-10070
i-Educar General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-284 1 PoC

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/. This manipulation causes improper access controls. The attack is possible to be carried out remotely. The exploit has been published and may be used.

CVE-2025-2750
Assimp General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-787 1 PoC

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-66497
Foxit PDF Reader General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-125 1 PoC

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.

CVE-2025-32472
SICK multiScan1XX General
5.3
MEDIUM
EPSS
1.0%
2025 CWE-400 1 PoC

The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowloris-type attack, causing the web page to become unresponsive.

CVE-2025-3388
oa_system General
5.3
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

CVE-2025-55627
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows authenticated attackers to create accounts with elevated privileges.

CVE-2025-10989
RuoYi General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the argument userIds results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-66498
Foxit PDF Reader General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-125 1 PoC

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.

CVE-2025-5440
RE6500 General
5.3
MEDIUM
EPSS
5.4%
2025 CWE-78 1 PoC

A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function NTP of the file /goform/NTP. The manipulation of the argument manual_year_select/manual_month_select/manual_day_select/manual_hour_select/manual_min_select/manual_sec_select leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-11050
i-Educar General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-285 1 PoC

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been published and may be used.

CVE-2025-57218
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C.

CVE-2025-2556
UTR Dashcam General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-798 1 PoC

A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknown functionality of the component Video Stream Handler. The manipulation leads to hard-coded credentials. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. Upgrading to version 2.89 and 2.90 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about these issues and acted very professional. Version 2.89 is fixing this issue for new customers and

CVE-2025-58582
Enterprise Analytics General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-770 1 PoC

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.

CVE-2025-2357
DCMTK General
5.3
MEDIUM
EPSS
0.2%
2025 CWE-119 2 PoCs

A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS Decoder. The manipulation leads to memory corruption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 3239a7915. It is recommended to apply a patch to fix this issue.

CVE-2025-41704
QUINT4-UPS/24DC/24DC/5/EIP General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-770 1 PoC

An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the core functionality.

CVE-2025-22376
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-338 1 PoC

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

CVE-2025-4016
Novel-Plus General
5.3
MEDIUM
EPSS
0.5%
2025 CWE-285 1 PoC

A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIndex of the file novel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.