5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-67074
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan.

CVE-2025-67278
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

CVE-2025-65345
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation.

CVE-2025-15488
Responsive Plus Web Windows
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as a shortcode.

CVE-2025-46203
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.

CVE-2025-1718
Relion 670/650 and SAM600-IO General
6.5
MEDIUM
EPSS
0.3%
2025 CWE-754 1 PoC

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk space management.

CVE-2025-46002
Software Genérico Web
6.5
MEDIUM
EPSS
1.2%
2025 2 PoCs

An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.

CVE-2025-65784
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.

CVE-2025-15574
Pocket WiFi 3.0 Cloud
6.5
MEDIUM
EPSS
0.0%
2025 CWE-330 1 PoC

When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the knowledge of the registration numbers can connect to the MQTT server and impersonate the dongle / inverters.

CVE-2025-61514
Software Genérico Networking
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVE-2025-23096
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.

CVE-2025-55341
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad.

CVE-2025-28367
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
12.7%
2025 0 PoCs

mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.

CVE-2025-65406
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file.

CVE-2025-21088
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-704 1 PoC

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.

CVE-2025-51403
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.

CVE-2025-29267
Software Genérico Database
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to obtain a sensitive information via the cid parameter in the GET request.

CVE-2025-2745
PI Web API Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.

CVE-2025-48414
cPH2 / cPP2 charging stations General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-798 2 PoCs

There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during development and provides an additional attack surface.

CVE-2025-57055
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator can supply a malicious URL via the pluginThemeUrl POST parameter. The server fetches the provided URL using curl_exec() without sufficient validation, allowing the attacker to force internal or external HTTP requests.