5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-1627
Qi Blocks Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-6557
Chrome Windows
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-45315
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.

CVE-2025-20973
Secure Folder General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type of Secure Folder.

CVE-2025-2475
Mattermost General
5.4
MEDIUM
EPSS
0.2%
2025 CWE-303 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.

CVE-2025-44185
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2025 3 PoCs

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.

CVE-2025-46171
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and crashing the forum.

CVE-2025-12908
Chrome General
5.4
MEDIUM
EPSS
0.1%
2025 CWE-20 1 PoC

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-45751
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.

CVE-2025-41410
Mattermost General
5.4
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import data to bypass email-based team access restrictions

CVE-2025-27579
ESP-MIner Web
5.4
MEDIUM
EPSS
0.1%
2025 CWE-352 1 PoC

In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka stratumUser) for a Bitaxe Bitcoin miner, or change the frequency and voltage settings.

CVE-2025-65230
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuration Streaming Destination input.

CVE-2025-27506
nocodb Web ⚡ nuclei
5.4
MEDIUM
EPSS
3.8%
2025 CWE-79 0 PoCs

NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-Scripting. The flaw occurs due to implementation of the client-side template engine ejs, specifically on file resetPassword.ts where the template is using the insecure function “<%-“, which is rendered by the function renderPasswordReset. This vulnerability is fixed in 0.258.0.

CVE-2025-11210
Chrome General
5.4
MEDIUM
EPSS
0.0%
2025 CWE-1300 1 PoC

Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-52392
Software Genérico Web
5.4
MEDIUM
EPSS
1.6%
2025 3 PoCs

Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts without restrictions, potentially gaining unauthorized administrative access. This vulnerability corresponds to CWE-307: Improper Restriction of Excessive Authentication Attempts.

CVE-2025-1015
Thunderbird Web
5.4
MEDIUM
EPSS
23.8%
2025 1 PoC

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If another user imported the address book, clicking on the link could result in opening a web page inside Thunderbird, and that page could execute (unprivileged) JavaScript. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.

CVE-2025-60299
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they view the affected comment thread.

CVE-2025-50477
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.

CVE-2025-55623
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using an ADB (Android Debug Bridge).

CVE-2025-63948
Software Genérico Web Database
5.4
MEDIUM
EPSS
0.0%
2025 1 PoC

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.