5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-20925
Samsung Notes General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read in applying binary of text data in Samsung Notes prior to version 4.4.26.71 allows local attackers to potentially read memory.

CVE-2025-24261
macOS General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVE-2025-53816
7-Zip General
5.5
MEDIUM
EPSS
0.1%
2025 CWE-122 2 PoCs

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

CVE-2025-58345
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write operation, leading to kernel memory exhaustion.

CVE-2025-20938
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.

CVE-2025-22407
Android General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-20947
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.

CVE-2025-24214
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2025 3 PoCs

A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.

CVE-2025-58348
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/confg_tspec write operation, leading to kernel memory exhaustion.

CVE-2025-24104
iOS and iPadOS General
5.5
MEDIUM
EPSS
3.3%
2025 2 PoCs

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.

CVE-2025-20918
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVE-2025-46711
Graphics DDK General
5.5
MEDIUM
EPSS
0.0%
2025 CWE-476 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer dereference kernel exceptions.

CVE-2025-54793
astro Web Cloud ⚡ nuclei
5.5
MEDIUM
EPSS
1.0%
2025 CWE-601 2 PoCs

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to arbitrary external domains by crafting URLs such as https://mydomain.com//malicious-site.com/. This increases the risk of phishing and other social engineering attacks. This affects sites that use on-demand rendering (SSR) with the Node or Cloudflare adapters. It does not affect static sites, or sites deployed to Netlify or Vercel. This issue i

CVE-2025-24215
iPadOS General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

CVE-2025-27163
Acrobat Reader General
5.5
MEDIUM
EPSS
0.1%
2025 CWE-125 1 PoC

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2025-24276
macOS General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

CVE-2025-58346
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_addts write operation, leading to kernel memory exhaustion.

CVE-2025-31187
macOS General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVE-2025-31191
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.1%
2025 4 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

CVE-2025-50085
MySQL Server Database
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availab