5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-24729
ElementInvader Addons for Elementor Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Stored XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.3.3.

CVE-2025-60672
Software Genérico Web Networking
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands executed via twsystem(). An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted HTTP request, leading to arbitrary command execution on the device.

CVE-2025-55629
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allow attackers to arbitrarily change other users' passwords via manipulation of the userName value.

CVE-2025-45746
ZKBio CVSecurity General
6.5
MEDIUM
EPSS
0.9%
2025 CWE-321 1 PoC

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and because access to the service console does not result in login access or data access in the context of the application software platform.

CVE-2025-65404
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream.

CVE-2025-56380
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter

CVE-2025-54335
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU Driver.

CVE-2025-5998
PPWP – Password Protect Pages Web Windows
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater roles can view content via the REST API.

CVE-2025-57926
Passster Web
6.5
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster content-protector allows Stored XSS.This issue affects Passster: from n/a through <= 4.2.18.

CVE-2025-65408
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file.

CVE-2025-20630
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-1287 1 PoC

Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.

CVE-2025-61224
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter

CVE-2025-56311
Software Genérico Web Networking
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF vulnerability on the reboot endpoint (/boaform/admin/formReboot). An attacker can craft a malicious webpage that, when visited by an authenticated administrator, causes the router to reboot without explicit user consent. This lack of CSRF protection on a sensitive administrative function can lead to denial of service by disrupting network availability.

CVE-2025-56747
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functions without proper role validation, allowing unauthorized course creation and management.

CVE-2025-44608
Software Genérico Web Database Cloud
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.

CVE-2025-30144
fast-jwt Web
6.5
MEDIUM
EPSS
2.6%
2025 CWE-345 3 PoCs

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly validate the iss claim based on the RFC 7519. The iss (issuer) claim validation within the fast-jwt library permits an array of strings as a valid iss value. This design flaw enables a potential attack where a malicious actor crafts a JWT with an iss claim structured as ['https://attacker-domain/', 'https://valid-iss']. Due to the permissive validation, the JWT will be deemed valid. Furthermore, if the application relies on external libraries like get-jwks that do not independentl

CVE-2025-60790
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

CVE-2025-59462
TLOC100-100 all Firmware versions General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-248 1 PoC

An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.

CVE-2025-60682
Software Genérico Web Networking Cloud
6.5
MEDIUM
EPSS
0.7%
2025 1 PoC

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed via system() without any sanitization or escaping. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device.

CVE-2025-52166
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator and access sensitive components and information.