5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-1550
Keras General
7.3
HIGH
EPSS
8.0%
2025 CWE-94 1 PoC

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.

CVE-2025-49144
notepad-plus-plus General
7.3
HIGH
EPSS
0.1%
2025 CWE-272 13 PoCs

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This is

CVE-2025-28020
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

CVE-2025-26125
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

CVE-2025-43947
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 1 PoC

Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.

CVE-2025-11446
upKeeper Manager General
7.3
HIGH
EPSS
0.0%
2025 CWE-532 1 PoC

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 before 5.2.12.

CVE-2025-12835
WooMulti Web Windows
7.3
HIGH
EPSS
0.1%
2025 1 PoC

The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any authenticated users, such as subscriber to delete arbitrary files on the server.

CVE-2025-58320
DIALink General
7.3
HIGH
EPSS
0.1%
2025 CWE-22 1 PoC

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

CVE-2025-22417
Android General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2025-45542
Software Genérico Web Database Cloud
7.3
HIGH
EPSS
0.7%
2025 2 PoCs

SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries.

CVE-2025-36463
BCM5820X Web
7.3
HIGH
EPSS
0.0%
2025 CWE-805 1 PoC

Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 4 (`WBIO_USH_ADD_RECORD`) and with an invalid `SendBufferSize`.

CVE-2025-3197
expand-object General
7.3
HIGH
EPSS
0.6%
2025 CWE-1321 1 PoC

Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like __proto__.

CVE-2025-22386
Software Genérico General
7.3
HIGH
EPSS
0.2%
2025 CWE-613 1 PoC

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.

CVE-2025-52490
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.

CVE-2025-28019
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component

CVE-2025-56132
Software Genérico General ⚡ nuclei
7.3
HIGH
EPSS
2.6%
2025 1 PoC

LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence of user accounts. Version 4.2 introduces user-based lockout mechanisms to mitigate brute-force attacks, user enumeration remains possible by default. In versions prior to 4.2, no such user-level protection is in place, only basic IP-based rate limiting is enforced. This IP-based protection can be bypassed by distributing requests across

CVE-2025-48621
Android General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2025-63602
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to IntelliBreeze.Maintenance.Service.sys) that lacks a properly secured DACL, allowing unprivileged users to interact with the driver and, as a result, the kernel. This can result in local privilege escalation, information disclosure, denial of service, and other unspecified impacts.

CVE-2025-21058
Routines General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attackers to potentially execute arbitrary code with SystemUI privilege.

CVE-2025-50063
Oracle Java SE Database
7.3
HIGH
EPSS
0.1%
2025 1 PoC

Vulnerability in Oracle Java SE (component: Install). The supported version that is affected is Oracle Java SE: 8u451. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS V