113 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2025-0111
🔥 KEV Cloud NGFW Web Networking Cloud
7.1
HIGH
EPSS
3.7%
2025 CWE-73 1 PoC

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue

CVE-2025-26633
🔥 KEV Windows 10 Version 1507 Windows
7.0
HIGH
EPSS
42.5%
2025 CWE-707 3 PoCs

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-0411
🔥 KEV 7-Zip General
7.0
HIGH
EPSS
52.4%
2025 CWE-693 10 PoCs

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the contex

CVE-2025-20362
🔥 KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Networking ⚡ nuclei
6.5
MEDIUM
EPSS
44.1%
2025 CWE-862 0 PoCs

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisc

CVE-2025-49706
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
75.0%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-55177
🔥 KEV WhatsApp Desktop for Mac General
5.4
MEDIUM
EPSS
0.7%
2025 1 PoC

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

CVE-2025-27915
🔥 KEV Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
26.1%
2025 0 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an

CVE-2025-4427
🔥 KEV Endpoint Manager Mobile Web ⚡ nuclei
5.3
MEDIUM
EPSS
91.3%
2025 CWE-288 2 PoCs

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

CVE-2025-31125
🔥 KEV vite Web ⚡ nuclei
5.3
MEDIUM
EPSS
82.6%
2025 CWE-200 5 PoCs

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.

CVE-2025-47827
🔥 KEV Software Genérico General
4.6
MEDIUM
EPSS
0.9%
2025 1 PoC

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

CVE-2025-47813
🔥 KEV Wing FTP Server General ⚡ nuclei
4.3
MEDIUM
EPSS
25.0%
2025 CWE-209 2 PoCs

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CVE-2025-47729
🔥 KEV archiving backend General
1.9
LOW
EPSS
4.1%
2025 CWE-912 1 PoC

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.