5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-46731
cms Web
7.3
HIGH
EPSS
0.9%
2025 CWE-1336 1 PoC

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

CVE-2025-4134
Avast Business Antivirus General
7.3
HIGH
EPSS
0.1%
2025 CWE-552 1 PoC

Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.

CVE-2025-9338
Armoury Crate General
7.3
HIGH
EPSS
0.0%
2025 CWE-119 1 PoC

A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.

CVE-2025-29621
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 1 PoC

Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.

CVE-2025-55912
Software Genérico Web
7.3
HIGH
EPSS
4.3%
2025 1 PoC

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler

CVE-2025-59424
LinkAce Web
7.3
HIGH
EPSS
0.0%
2025 CWE-79 1 PoC

LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. The application fails to properly sanitize the username field before it is rendered in the audit log. An authenticated attacker can set a malicious JavaScript payload as their username. When an action performed by this user is recorded (e.g., generate or revoke an API token), the payload is stored in the database. The script is then executed in the browser of any user, particularly administrators, who views the /system/audit

CVE-2025-48548
Android General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

CVE-2025-4272
Control Console Web
7.3
HIGH
EPSS
0.1%
2025 CWE-427 1 PoC

A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\csCAPI.dll of the component GCUService. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

CVE-2025-27829
Software Genérico Networking
7.3
HIGH
EPSS
0.4%
2025 1 PoC

An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces. That could result in a denial of the multicast routing service on the firewall.

CVE-2025-24076
Windows 11 version 22H2 Windows
7.3
HIGH
EPSS
3.0%
2025 CWE-284 1 PoC

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

CVE-2025-35036
Hibernate Validator General
7.3
HIGH
EPSS
1.7%
2025 CWE-94 1 PoC

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Lan

CVE-2025-20903
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

CVE-2025-20957
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.

CVE-2025-3025
CCleaner Windows
7.3
HIGH
EPSS
0.0%
2025 CWE-552 1 PoC

Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local user to gain SYSTEM privileges via exploiting insecure file delete operations. Reported in CCleaner v. 6.33.11465. This issue affects CCleaner: before < 6.36.11508.

CVE-2025-55618
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field in navigation app which then get rendered.

CVE-2025-60375
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 2 PoCs

The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without providing valid credentials.

CVE-2025-23094
Software Genérico General
7.3
HIGH
EPSS
2.1%
2025 1 PoC

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the same privilege level as the web access process.

CVE-2025-28026
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.

CVE-2025-3029
Firefox General
7.3
HIGH
EPSS
0.7%
2025 1 PoC

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was fixed in Firefox 137, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

CVE-2025-66824
Software Genérico Web
7.3
HIGH
EPSS
0.1%
2025 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.