5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-39538
WP-Advanced-Search General
6.6
MEDIUM
EPSS
0.3%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search wp-advanced-search allows Upload a Web Shell to a Web Server.This issue affects WP-Advanced-Search: from n/a through <= 3.3.9.4.

CVE-2025-24198
iOS and iPadOS General
6.6
MEDIUM
EPSS
0.1%
2025 1 PoC

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.

CVE-2025-21056
Retail Mode General
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on their own devices.

CVE-2025-70342
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe.

CVE-2025-5273
mcp-markdownify-server General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-552 1 PoC

All versions of the package mcp-markdownify-server are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.

CVE-2025-63953
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

CVE-2025-36539
PI Data Archive General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-248 1 PoC

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service.

CVE-2025-50154
Windows 10 Version 1507 Windows
6.5
MEDIUM
EPSS
24.3%
2025 CWE-200 4 PoCs

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-20149
IOS Networking
6.5
MEDIUM
EPSS
0.0%
2025 CWE-120 1 PoC

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the CLI prompt. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

CVE-2025-56162
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modify database data, including dumping admin password hashes; (b) write web-shell files or invoke xp_cmdshell, leading to remote code execution on servers configured with sufficient DB privileges.

CVE-2025-50076
MySQL Server Database
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.25. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2025-27450
Endress+Hauser MEAC300-FNADE4 Web
6.5
MEDIUM
EPSS
0.2%
2025 CWE-614 1 PoC

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.

CVE-2025-2278
Server General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-284 1 PoC

Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID.

CVE-2025-52162
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the RSSReader endpoint. This vulnerability allows attackers to access sensitive data via providing a crafted XML input.

CVE-2025-52168
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system.

CVE-2025-35021
CPX Networking
6.5
MEDIUM
EPSS
0.1%
2025 CWE-1188 2 PoCs

By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth attempt, and from there, relay connections.

CVE-2025-24578
ElementInvader Addons for Elementor Web
6.5
MEDIUM
EPSS
0.3%
2025 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.3.0.

CVE-2025-45512
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.

CVE-2025-9776
CatFolders – WordPress Media Library Folders & Categories Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Injection via the CSV Import contents in all versions up to, and including, 2.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-1636
Remote Desktop Manager Windows
6.5
MEDIUM
EPSS
0.3%
2025 CWE-200 1 PoC

Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic.