5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-24907
Pentaho Data Integration & Analytics Web
6.8
MEDIUM
EPSS
0.4%
2025 CWE-35 1 PoC

Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35)   Description   Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.2, including 9.3.x and 8.3.x, do not sanitize a user input used as a file path through the CGG Draw API.   Impact   This allows attackers to traverse the file system to access files or directories tha

CVE-2025-36530
Mattermost General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions.

CVE-2025-14803
NEX-Forms Web Windows
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

CVE-2025-14095
ABL90 FLEX and ABL90 FLEX PLUS Analyzers General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-284 1 PoC

A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user with physical access to the analyzer, the possibility to gain unauthorized access to functionalities outside the restricted environment. The vulnerability is due to weakness in the design of access control implementation in application software.  Other related CVE's are CVE-2025-14096 & CVE-2025-14097. Affected customers have been informed about this vulnerability. This CVE is being published to provide transparency. Required configuration for

CVE-2025-59095
Kaba exos 9300 General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-798 2 PoCs

The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecrypt" in the library Kaba.EXOS.common.dll. This algorithm uses a simple XOR encryption technique combined with a cryptographic key (cryptoKey) to transform each character of the input string. However, it's important to note that this implementation does not provide strong encryption and should not be considered secure for sensitive data. It's more of a custom encryption approach rather than a common algorithm used in cryptographic applications. The k

CVE-2025-0223
Protected Folder General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-476 1 PoC

A vulnerability was found in IObit Protected Folder up to 13.6.0.5. It has been classified as problematic. Affected is the function 0x8001E000/0x8001E00C/0x8001E004/0x8001E010 in the library IURegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-57438
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level user can bypass these controls by intercepting and modifying requests.

CVE-2025-15433
Shared Files Web Windows
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector

CVE-2025-47415
TOUCHSCREENS x60, x70 series General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061 - (no fix released, product discontinued)   For x70   The Affected Firmware:- 3.000.0110.001  and versions below The Fixed Firmware:- 3.001.0031.001

CVE-2025-5382
Server General
6.8
MEDIUM
EPSS
0.2%
2025 CWE-284 1 PoC

Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.

CVE-2025-27448
Endress+Hauser MEAC300-FNADE4 Web
6.8
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.

CVE-2025-14435
Mattermost Web
6.8
MEDIUM
EPSS
0.0%
2025 CWE-770 1 PoC

Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.

CVE-2025-26412
SIM7600G Modem General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-912 2 PoCs

The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interacts directly with the modem via AT commands.

CVE-2025-3938
Niagara Framework Windows
6.8
MEDIUM
EPSS
0.2%
2025 CWE-325 1 PoC

Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-7371
Okta On-Premises Provisioning Agent General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-532 1 PoC

Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by this vulnerability if the following preconditions are met: Local server running OPP agent with versions >=2.2.1 and <= 2.3.0, and User account has had an administrator-initiated password reset while using the affected versions.

CVE-2025-8864
YugabyteDB Anywhere General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-532 1 PoC

Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs

CVE-2025-27892
Software Genérico Web Database ⚡ nuclei
6.8
MEDIUM
EPSS
2.8%
2025 1 PoC

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

CVE-2025-41705
QUINT4-UPS/24DC/24DC/5/EIP General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-523 1 PoC

An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.

CVE-2025-2600
Remote Desktop Manager Windows
6.8
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.