5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-57822
next.js General ⚡ nuclei
6.5
MEDIUM
EPSS
6.5%
2025 CWE-918 0 PoCs

Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in Next.js versions 14.2.32 and 15.4.7. All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the next() function.

CVE-2025-55668
Apache Tomcat Web
6.5
MEDIUM
EPSS
0.0%
2025 CWE-384 1 PoC

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

CVE-2025-27803
cPH2 / cPP2 charging stations General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-306 2 PoCs

The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.

CVE-2025-22921
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

CVE-2025-3472
Ocean Extra Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
17.3%
2025 CWE-94 0 PoCs

The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.

CVE-2025-53771
Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
39.6%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-46000
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVE-2025-45619
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function

CVE-2025-54767
LPAR2RRD General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-648 1 PoC

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

CVE-2025-65427
Software Genérico Web Networking
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

CVE-2025-10540
iMonitor EAM General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-319 2 PoCs

iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credentials, keylogger data, and personally identifiable information) and tamper with traffic. This allows both unauthorized disclosure and modification of data, including issuing arbitrary commands to client agents.

CVE-2025-44895
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.

CVE-2025-54603
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

CVE-2025-47906
os/exec General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

CVE-2025-59214
Windows 10 Version 1507 Windows
6.5
MEDIUM
EPSS
0.1%
2025 CWE-200 3 PoCs

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-54327
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 2 PoCs

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validation in the VTS driver leads to an arbitrary write.

CVE-2025-55070
Mattermost General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

CVE-2025-46425
Dell Storage Manager General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-611 1 PoC

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

CVE-2025-63212
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions without providing any credentials. This attack requires the legitimate user (admin) to have previously closed the browser window without logging out.