5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-8123
deer-wms-2 Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-11100
DIR-823X General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-77 1 PoC

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVE-2025-49195
SICK Media Server General
5.3
MEDIUM
EPSS
0.4%
2025 CWE-307 1 PoC

The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.

CVE-2025-12246
chatwoot Web
5.3
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/IframeLoader.vue of the component Admin Interface. The manipulation of the argument Link results in cross site scripting. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-2733
OpenManus General
5.3
MEDIUM
EPSS
0.7%
2025 CWE-78 1 PoC

A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13. This affects an unknown part of the file app/tool/python_execute.py of the component Prompt Handler. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-4999
FGW3000-AH Web
5.3
MEDIUM
EPSS
1.9%
2025 CWE-77 1 PoC

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function sub_4153FC of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulation of the argument supplicant_rnd_id_en leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-1716
picklescan General
5.3
MEDIUM
EPSS
16.2%
2025 CWE-184 3 PoCs

picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model, when scanned with picklescan, would pass security checks and appear to be safe, when it could instead prove to be problematic.

CVE-2025-7557
Voting System Web Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability has been found in code-projects Voting System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/voters_row.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-9985
Featured Image from URL (FIFU) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
2.1%
2025 CWE-532 0 PoCs

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

CVE-2025-7103
BoyunCMS Web
5.3
MEDIUM
EPSS
0.2%
2025 CWE-918 1 PoC

A vulnerability was found in BoyunCMS up to 1.4.20. It has been rated as critical. This issue affects some unknown processing of the file /application/pay/controller/Index.php of the component curl. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-32946
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-282 1 PoC

This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.

CVE-2025-27936
Mattermost General
5.3
MEDIUM
EPSS
0.2%
2025 CWE-208 1 PoC

Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.

CVE-2025-8161
deer-wms-2 Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. Affected by this vulnerability is an unknown functionality of the file /system/role/export. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-10430
Pet Grooming Management Software Web Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/barcode.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVE-2025-10602
Online Exam Form Submission Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s1.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

CVE-2025-3697
Web-based Pharmacy Product Management System Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-product.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-9609
i-Educar General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulation results in improper authorization. The attack can be executed remotely. The exploit has been made public and could be used.

CVE-2025-6850
Simple Forum Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forum1.php. The manipulation of the argument File leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-27374
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, 1330, 1380, 1480, 2400. The lack of a length check leads to out-of-bounds writes.

CVE-2025-10675
platform General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-285 1 PoC

A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of the file /attribute/queryAll. Performing manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.