5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-63293
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API.

CVE-2025-43720
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.

CVE-2025-51867
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM using other users' credits via sensitive information gained by the /browse/stories endpoint.

CVE-2025-2820
Product family GLx and CWx General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-400 1 PoC

An authenticated attacker can compromise the availability of the device via the network

CVE-2025-50420
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

CVE-2025-12685
WPBookit Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.

CVE-2025-52078
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint.

CVE-2025-51459
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hub._sanitize_filename and plugins_util.scan_plugins.

CVE-2025-57305
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

CVE-2025-57428
Software Genérico Networking
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands.

CVE-2025-60693
Software Genérico Web Networking
6.5
MEDIUM
EPSS
2.3%
2025 2 PoCs

A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to six user-supplied CGI parameters matching <parameter>_0~5 into a fixed-size buffer (a2) without proper bounds checking, appending colon delimiters during concatenation. Remote attackers can exploit this vulnerability via specially crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.

CVE-2025-10720
WP Private Content Plus General
6.5
MEDIUM
EPSS
0.2%
2025 2 PoCs

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

CVE-2025-27804
cPH2 / cPP2 charging stations Web
6.5
MEDIUM
EPSS
0.9%
2025 CWE-78 2 PoCs

Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted message to a certain MQTT topic arbitrary OS commands can be executed with root permissions.

CVE-2025-50688
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2025 1 PoC

A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uploaded, the attacker can trigger the execution of arbitrary commands on the target system, allowing for remote code execution. This could lead to escalation of privileges depending on the privileges of the web server process. The attack does not require physical access and can be conducted remotely, p

CVE-2025-45663
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

CVE-2025-8994
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from th

CVE-2025-58364
cups General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-20 1 PoC

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups & cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was n

CVE-2025-70095
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

CVE-2025-23095
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.

CVE-2025-27980
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.