5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-34065
IP camera, DVR, and NVR Devices General
6.9
MEDIUM
EPSS
0.4%
2025 CWE-290 2 PoCs

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.

CVE-2025-13203
Simple Cafe Ordering System Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code of the file /addmem.php. Executing manipulation of the argument studentnum can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-0390
Jeewms General
6.9
MEDIUM
EPSS
0.2%
2025 CWE-24 1 PoC

A vulnerability classified as critical was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This vulnerability affects unknown code of the file /wmOmNoticeHController.do. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 20250101 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2025-21031
Samsung Mobile Devices Web
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.

CVE-2025-32876
Software Genérico General
6.8
MEDIUM
EPSS
0.1%
2025 3 PoCs

An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Legacy Pairing. In BLE Legacy Pairing, the Short-Term Key (STK) can be easily guessed. This requires knowledge of the Temporary Key (TK), which, in the case of the COROS Pace 3, is set to 0 due to the Just Works pairing method. An attacker within Bluetooth range can therefore perform sniffing attacks, allowing eavesdropping on the communication.

CVE-2025-27591
below General
6.8
MEDIUM
EPSS
0.1%
2025 12 PoCs

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.

CVE-2025-24908
Pentaho Data Integration & Analytics General
6.8
MEDIUM
EPSS
0.3%
2025 CWE-35 1 PoC

Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35)   Description   Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.2, including 9.3.x and 8.3.x, do not sanitize a user input used as a file path through the UploadFile service.   Impact   This allows attackers to traverse the file system to access files or directori

CVE-2025-63892
Software Genérico Web
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument name/description causes stored cross site scripting.

CVE-2025-2055
MapPress Maps for WordPress Web Windows
6.8
MEDIUM
EPSS
0.5%
2025 1 PoC

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2025-12351
S35 3M/5M/8M/Pinhole/Kit Camera Cloud
6.8
MEDIUM
EPSS
0.0%
2025 CWE-639 1 PoC

Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service or offering (S35 Pinhole/Kit Camera to version 2025.08.28, S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera to version 2025.08.22, S35 Thermal Camera to version 2025.08.26).

CVE-2025-26409
Wattsense Bridge General
6.8
MEDIUM
EPSS
0.2%
2025 CWE-1299 3 PoCs

A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.

CVE-2025-59713
Snipe-IT General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-502 1 PoC

Snipe-IT before 8.1.18 allows unsafe deserialization.

CVE-2025-20897
Secure Folder General
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Secure Folder prior to version 1.9.20.50 in Android 14, 1.8.11.0 in Android 13, and 1.7.04.0 in Android 12 allows local attacker to access data in Secure Folder.

CVE-2025-6515
oatpp-mcp General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-330 1 PoC

The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers with access to the oatpp-mcp server to guess future session IDs and hijack legitimate client MCP sessions, returning malicious responses from the oatpp-mcp server.

CVE-2025-60674
Software Genérico Networking
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 bytes, causing a stack overflow. An attacker with physical access or control over a USB device can exploit this vulnerability to potentially execute arbitrary code on the device.

CVE-2025-9978
Jeg Kit for Elementor Web Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting vulnerability.

CVE-2025-11984
GitLab DevOps
6.8
MEDIUM
EPSS
0.0%
2025 CWE-288 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

CVE-2025-53744
FortiOS General
6.8
MEDIUM
EPSS
0.2%
2025 CWE-266 1 PoC

An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.

CVE-2025-3649
LightPress Lightbox Web Windows
6.8
MEDIUM
EPSS
0.3%
2025 1 PoC

The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.

CVE-2025-26465
Software Genérico Networking
6.8
MEDIUM
EPSS
61.2%
2025 CWE-390 9 PoCs

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.