5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-20905
Samsung Mobile Devices General
6.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.

CVE-2025-21017
Blockchain Keystore General
6.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-14697
Sixun Shanghui Group Business Management System General
6.3
MEDIUM
EPSS
0.1%
2025 CWE-552 1 PoC

A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this issue is some unknown functionality of the file /ExportFiles/. The manipulation results in files or directories accessible. The attack may be launched remotely. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-67886
Software Genérico Web
6.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload new translated pages to the website.

CVE-2025-20941
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.

CVE-2025-20972
Samsung Flow General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.

CVE-2025-58340
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_delts write operation, leading to kernel memory exhaustion.

CVE-2025-20981
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-21000
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.

CVE-2025-65841
Software Genérico Cloud
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings using a weak obfuscation scheme. The password is "encrypted" through predictable byte-substitution that can be trivially reversed, allowing immediate recovery of the plaintext value. Any attacker who can read this settings file can fully compromise the victim's Aquarius account by importing the stolen configuration into their own client or login through the vendor website. This results in complete account takeover, unauthorized access to cloud-syn

CVE-2025-0395
glibc General
6.2
MEDIUM
EPSS
0.1%
2025 CWE-131 4 PoCs

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.

CVE-2025-54389
aide General
6.2
MEDIUM
EPSS
0.0%
2025 CWE-117 1 PoC

AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. An attacker can craft a malicious filename by including terminal escape sequences to hide the addition or removal of the file from the report and/or tamper with the log output. A local user might exploit this to bypass the AIDE detection of malicious files. Additionally the output of extended attribute key names and symbolic links targets are also not properly neutralized. This issue has been patched in version 0.19.2. A workaround involves configurin

CVE-2025-21004
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.

CVE-2025-20978
PENUP General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.

CVE-2025-58344
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation in a /proc/driver/unifi0/conn_log_event_burst_to_us write operation, leading to kernel memory exhaustion.

CVE-2025-20910
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

CVE-2025-60419
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.

CVE-2025-20970
Bixby Vision General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege.

CVE-2025-21059
Samsung Health General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

CVE-2025-20997
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.