5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-59439
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and Modem 5123. Incorrect handling of NAS Registration messages leads to a Denial of Service because of Improper Handling of Exceptional Conditions.

CVE-2025-70242
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.

CVE-2025-56301
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2025 1 PoC

An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowing attackers to corrupt exception handling and privilege state transitions via a flawed interaction between exception handling and MRET return mechanisms in the CSR logic when an exception is triggered during MRET execution. The Control and Status Register (CSR) logic has a flawed interaction between exception handling and exception return (MRET) mechanisms which can cause faulty trap behavior. When the MRET instruction is executed in machine mode without being in an exceptio

CVE-2025-70227
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.

CVE-2025-70238
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.

CVE-2025-70886
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

CVE-2025-70252
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.

CVE-2025-70241
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

CVE-2025-70249
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.

CVE-2025-70251
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.

CVE-2025-69420
OpenSSL General
7.5
HIGH
EPSS
0.5%
2025 CWE-754 1 PoC

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value

CVE-2025-70237
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.

CVE-2025-69421
OpenSSL General
7.5
HIGH
EPSS
0.1%
2025 CWE-476 1 PoC

Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, causing a crash. The vulnerability is limited to Denial of Service and cannot be escalated to achieve c

CVE-2025-70244
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.

CVE-2025-9230
OpenSSL Web
7.5
HIGH
EPSS
0.0%
2025 CWE-125 1 PoC

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password

CVE-2025-70234
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.

CVE-2025-63946
Software Genérico Windows
7.4
HIGH
EPSS
0.0%
2025 1 PoC

A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

CVE-2025-58407
Graphics DDK Web
7.4
HIGH
EPSS
0.0%
2025 CWE-367 1 PoC

Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.

CVE-2025-30460
macOS General
7.4
HIGH
EPSS
0.1%
2025 1 PoC

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

CVE-2025-21399
Microsoft Edge Update Setup General
7.4
HIGH
EPSS
0.2%
2025 CWE-426 2 PoCs

Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability