5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-2363
VBlog General
5.3
MEDIUM
EPSS
0.4%
2025 CWE-22 1 PoC

A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-8041
Firefox General
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in Firefox 141.

CVE-2025-11436
OpnForm General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-434 1 PoC

A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit is now public and may be used. The patch is identified as 95c3e23856465d202e6aec10bdb6ee0688b5305a. It is advisable to implement a patch to correct this issue.

CVE-2025-25473
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.

CVE-2025-70236
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.

CVE-2025-20221
Cisco IOS XE Software Networking
5.3
MEDIUM
EPSS
0.1%
2025 CWE-200 1 PoC

A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the affected device. A successful exploit could allow the attacker to bypass the Layer 3 and Layer 4 traffic filters and inject a crafted packet into the network.

CVE-2025-2321
springboot-openai-chatgpt Web Networking
5.3
MEDIUM
EPSS
0.1%
2025 CWE-840 2 PoCs

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this issue is some unknown functionality of the file /api/mjkj-chat/cgform-api/addData/. The manipulation of the argument chatUserID leads to business logic errors. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in an

CVE-2025-2742
ruoyi-vue-pro Web
5.3
MEDIUM
EPSS
0.2%
2025 CWE-22 1 PoC

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-34504
KodExplorer General
5.3
MEDIUM
EPSS
0.2%
2025 CWE-601 1 PoC

KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.

CVE-2025-3120
Apartment Visitors Management System Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument apartmentno leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2025-3018
Online Eyewear Shop Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-12841
Bookit Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options.

CVE-2025-54333
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the get_vs4l_profiler_node function.

CVE-2025-2622
snail-job General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-502 2 PoCs

A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the component Workflow-Task Management Module. The manipulation of the argument nodeExpression leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8124
deer-wms-2 Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/unallocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-5445
RE6500 General
5.3
MEDIUM
EPSS
7.5%
2025 CWE-78 1 PoC

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkFWByBBS. The manipulation of the argument type/ch/ssidhex/security/extch/pwd/mode/ip/nm/gw leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-10086
platform General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-285 1 PoC

A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionController. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. Affects another part than CVE-2025-9936.

CVE-2025-59685
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Kazaar 1.25.12 allows a JWT with none in the alg field.

CVE-2025-4538
kkFileView General
5.3
MEDIUM
EPSS
0.3%
2025 CWE-434 1 PoC

A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-1166
Food Menu Manager Web
5.3
MEDIUM
EPSS
0.2%
2025 CWE-434 1 PoC

A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file endpoint/update.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.