5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-25967
Software Genérico Web
6.8
MEDIUM
EPSS
0.4%
2025 1 PoC

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

CVE-2025-59709
Software Genérico General
6.8
MEDIUM
EPSS
0.2%
2025 1 PoC

An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.

CVE-2025-6037
Vault Web
6.8
MEDIUM
EPSS
0.1%
2025 CWE-295 1 PoC

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In this configuration, an attacker may be able to craft a malicious certificate that could be used to impersonate another user. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

CVE-2025-24272
macOS General
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVE-2025-26637
Windows 10 Version 1507 Windows
6.8
MEDIUM
EPSS
1.4%
2025 CWE-693 1 PoC

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2025-8023
Mattermost General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious path components, potentially enabling malicious file placement outside intended directories.

CVE-2025-0549
GitLab DevOps
6.8
MEDIUM
EPSS
0.1%
2025 CWE-288 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form submission through minimal user interaction.

CVE-2025-49222
Mattermost General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-434 1 PoC

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared channels that could potentially be placed in arbitrary filesystem directories.

CVE-2025-52363
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative access

CVE-2025-14973
Recipe Card Blocks Lite Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks.

CVE-2025-9336
Armoury Crate General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-121 1 PoC

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

CVE-2025-13407
Gravity Forms Web Windows
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

CVE-2025-25984
Software Genérico General
6.8
MEDIUM
EPSS
0.2%
2025 1 PoC

An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.

CVE-2025-20984
Samsung Mobile Devices Cloud
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch.

CVE-2025-56448
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims.

CVE-2025-3742
Responsive Lightbox & Gallery Web Windows
6.8
MEDIUM
EPSS
0.3%
2025 1 PoC

The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-9337
Armoury Crate General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-476 1 PoC

A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

CVE-2025-56463
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.

CVE-2025-32063
Infotainment system ECU Networking
6.8
MEDIUM
EPSS
0.0%
2025 CWE-306 2 PoCs

There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a specific systemd service, and as a result, the following developer features will be activated: the disabled firewall and the launched SSH server. First identified on Nissan Leaf ZE1 manufactured in 2020.

CVE-2025-12502
attention-bar Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users such as administrator to perform SQL injection attacks