5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-27410
pwndoc DevOps
6.5
MEDIUM
EPSS
16.5%
2025 CWE-23 1 PoC

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their content. By overwriting an included `.js` file and restarting the container, this allows for Remote Code Execution as an administrator. The remote code execution occurs because any user with the `backups:create` and `backups:update` (only administrators by default) is able to overwrite any file on the system. Version 1.2.0 fixes the issue.

CVE-2025-50234
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2025 2 PoCs

MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function, which utilizes a hard-coded key Mc_Encryption_Key (bD2voYwPpNuJ7B8), defined in the db.php file. The decrypted URL is passed to the geturl() method, which uses cURL to make a request to the URL without proper security checks. An attacker can craft a malicious encrypted pic parameter, which, when decrypted, points to internal addresses or local file paths (such as http://127.0.

CVE-2025-41678
mbNET.mini Database
6.5
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.

CVE-2025-60673
Software Genérico Web Networking
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi is stored in NVRAM and later used by librcm.so to construct iptables commands executed via twsystem(). An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted HTTP request, leading to arbitrary command execution on the device.

CVE-2025-27457
Endress+Hauser MEAC300-FNADE4 General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-319 1 PoC

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.

CVE-2025-0441
Chrome General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information from the system via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-13922
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied parameters and lack of SQL query parameterization. This makes it possible for authenticated attackers, with Contributor-level access and above who have AI metabox permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information

CVE-2025-50565
Software Genérico Database
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Doubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiated by an attacker.

CVE-2025-24948
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.

CVE-2025-64493
SuiteCRM-Core Web Database
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and does not require administrative access. This issue is fixed in version 8.9.1.

CVE-2025-3111
GitLab DevOps
6.5
MEDIUM
EPSS
0.5%
2025 CWE-770 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVE-2025-32944
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-248 1 PoC

The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.  If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. If the yauzl library encounters a filename that is considered illegal, it raises an exception that is uncaught by PeerTube, leading to a crash which repeats infinitely on startup.

CVE-2025-51089
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow.

CVE-2025-61540
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.

CVE-2025-0435
Chrome General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

CVE-2025-3028
Firefox Web
6.5
MEDIUM
EPSS
0.7%
2025 1 PoC

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

CVE-2025-20072
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-704 1 PoC

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.

CVE-2025-25953
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive information.

CVE-2025-11705
Anti-Malware Security and Brute-Force Firewall Web Networking Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to a missing capability check combined with an information exposure in several GOTMLS_* AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-27458
Endress+Hauser MEAC300-FNADE4 General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-327 1 PoC

The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from the server to the client, is encrypted by the client and sent back. The server does the same encryption locally and if the responses match it is prooven that the client knows the correct password. Since all VNC communication is unencrypted, an attacker can obtain the challenge and response and try to derive the password from this information.