113 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2025-32706
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
1.3%
2025 CWE-20 2 PoCs

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-32709
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.8%
2025 CWE-416 1 PoC

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2025-24985
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
1.7%
2025 CWE-190 3 PoCs

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

CVE-2025-30400
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.8%
2025 CWE-416 1 PoC

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2025-60710
🔥 KEV Windows 11 Version 24H2 Windows
7.8
HIGH
EPSS
29.7%
2025 CWE-59 2 PoCs

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2025-59230
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
3.7%
2025 CWE-284 2 PoCs

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2025-24990
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
2.8%
2025 CWE-822 2 PoCs

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.

CVE-2025-6218
🔥 KEV WinRAR General
7.8
HIGH
EPSS
6.6%
2025 CWE-22 5 PoCs

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.

CVE-2025-29824
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.3%
2025 CWE-416 2 PoCs

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-41244
🔥 KEV VCF operations General
7.8
HIGH
EPSS
0.6%
2025 CWE-267 3 PoCs

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVE-2025-20352
🔥 KEV IOS Networking
7.7
HIGH
EPSS
2.7%
2025 CWE-121 1 PoC

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisc

CVE-2025-11371
🔥 KEV CentreStack and TrioFox General ⚡ nuclei
7.5
HIGH
EPSS
70.1%
2025 4 PoCs

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

CVE-2025-30397
🔥 KEV Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
20.7%
2025 CWE-843 4 PoCs

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

CVE-2025-54313
🔥 KEV eslint-config-prettier Windows
7.5
HIGH
EPSS
11.6%
2025 CWE-506 3 PoCs

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CVE-2025-61884
🔥 KEV Oracle Configurator Web Database ⚡ nuclei
7.5
HIGH
EPSS
48.3%
2025 3 PoCs

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2025-4428
🔥 KEV Endpoint Manager Mobile Web
7.2
HIGH
EPSS
26.2%
2025 CWE-94 3 PoCs

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

CVE-2025-2749
🔥 KEV Xperience General
7.2
HIGH
EPSS
3.8%
2025 CWE-22 1 PoC

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.

CVE-2025-66644
🔥 KEV ArrayOS AG General
7.2
HIGH
EPSS
1.2%
2025 CWE-78 1 PoC

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

CVE-2025-14611
🔥 KEV CentreStack and TrioFox General ⚡ nuclei
7.1
HIGH
EPSS
58.3%
2025 1 PoC

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.