5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-25474
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.

CVE-2025-12573
Bookingor Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, allowing low-privileged users to delete Bookingor WordPress plugin through 1.0.12 data.

CVE-2025-20362
🔥 KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Networking ⚡ nuclei
6.5
MEDIUM
EPSS
44.1%
2025 CWE-862 0 PoCs

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisc

CVE-2025-25478
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.

CVE-2025-64402
Apache OpenOffice Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "OLE objects" linked to external files would load the contents of those files without prompting the user for permission to do so. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.

CVE-2025-59686
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.

CVE-2025-50078
MySQL Server Database
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2025-54249
Adobe Experience Manager General ⚡ nuclei
6.5
MEDIUM
EPSS
6.3%
2025 CWE-918 0 PoCs

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass security controls allowing unauthorized read access.

CVE-2025-34490
MailEssentials Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-611 1 PoC

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.

CVE-2025-49200
SICK Field Analytics General
6.5
MEDIUM
EPSS
0.3%
2025 CWE-200 1 PoC

The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.

CVE-2025-8881
Chrome General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-56799
Software Genérico General
6.5
MEDIUM
EPSS
2.5%
2025 1 PoC

Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.

CVE-2025-60699
Software Genérico Web Networking
6.5
MEDIUM
EPSS
1.6%
2025 1 PoC

A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `global.so` binary. The `getSaveConfig` function retrieves the `http_host` parameter from user input via `websGetVar` and copies it into a fixed-size stack buffer (`v13`) using `strcpy()` without performing any length checks. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted HTTP request to the router's web interface, potentially leading to arbitrary code execution.

CVE-2025-22377
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol implementation because of a mismatch between the actual length of the payload and the length declared within the payload.

CVE-2025-23101
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privilege escalation.

CVE-2025-21574
MySQL Cluster Database
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2025-49706
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
75.0%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-30446
macOS General
6.5
MEDIUM
EPSS
0.5%
2025 1 PoC

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app with root privileges may be able to modify the contents of system files.

CVE-2025-58587
Baggage Analytics General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-307 1 PoC

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials.

CVE-2025-58591
Baggage Analytics General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information.