2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-69418
OpenSSL Web
4.0
MEDIUM
EPSS
0.0%
2025 CWE-325 1 PoC

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not

CVE-2025-20960
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

CVE-2025-53910
Mattermost Confluence Plugin Web
4.0
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.

CVE-2025-44001
Mattermost Confluence Plugin Web
4.0
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.

CVE-2025-8594
Pz-LinkCard Web Windows
3.8
LOW
EPSS
0.0%
2025 1 PoC

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

CVE-2025-14573
Mattermost Web
3.8
LOW
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561

CVE-2025-58578
Enterprise Analytics Web
3.8
LOW
EPSS
0.1%
2025 CWE-770 1 PoC

A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.

CVE-2025-25228
Virtuemart component for Joomla Web Database
3.8
LOW
EPSS
0.2%
2025 CWE-89 1 PoC

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.

CVE-2025-8889
Compress & Upload Web Windows
3.8
LOW
EPSS
0.0%
2025 2 PoCs

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2025-53971
Mattermost Web
3.8
LOW
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.

CVE-2025-53857
Mattermost Confluence Plugin Web
3.7
LOW
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.

CVE-2025-49221
Mattermost Confluence Plugin Web
3.7
LOW
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.

CVE-2025-51586
Software Genérico Web ⚡ nuclei
3.7
LOW
EPSS
1.1%
2025 2 PoCs

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

CVE-2025-14592
GitLab DevOps Web
3.7
LOW
EPSS
0.0%
2025 CWE-862 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

CVE-2025-50065
Oracle GraalVM for JDK Web Database
3.7
LOW
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version that is affected is Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2025-11244
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content Web Windows
3.7
LOW
EPSS
0.0%
2025 CWE-285 1 PoC

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the `pp_get_ip_address()` function when the "Use transients" feature is enabled. This makes it possible for attackers to bypass authorization by spoofing these headers with the IP address of a legitimately authenticated user, granted the "Use transients" option is enabled (non-default

CVE-2025-54352
WordPress Web Windows
3.7
LOW
EPSS
0.1%
2025 CWE-669 3 PoCs

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

CVE-2025-3650
jQuery Colorbox Web Windows
3.5
LOW
EPSS
0.0%
2025 1 PoC

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

CVE-2025-14594
GitLab DevOps Web
3.5
LOW
EPSS
0.0%
2025 CWE-639 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

CVE-2025-1523
Ultimate Dashboard Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).