5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-9910
jsondiffpatch Web
4.7
MEDIUM
EPSS
0.0%
2025 CWE-79 3 PoCs

Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in html formatter on a private website.

CVE-2025-5054
Apport DevOps
4.7
MEDIUM
EPSS
0.0%
2025 CWE-362 3 PoCs

Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before `consistency_checks`, which attempts to detect if the crashing process had been replaced. Because of this, if a process crashed and was quickly replaced with a containerized one, apport could be made to forward the core dump to the container, potentially leaking sensitive information.

CVE-2025-22206
JS Jobs component for Joomla Web Database
4.7
MEDIUM
EPSS
0.8%
2025 CWE-89 1 PoC

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.

CVE-2025-1425
InkPad Color 3 General
4.7
MEDIUM
EPSS
0.1%
2025 CWE-269 1 PoC

A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.

CVE-2025-4598
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2025 CWE-364 7 PoCs

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacke

CVE-2025-32093
Mattermost General
4.7
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via improper permission validation.

CVE-2025-10281
bbot Web
4.7
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL.

CVE-2025-60250
Go2 General
4.7
MEDIUM
EPSS
0.0%
2025 CWE-321 1 PoC

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the 2841ae97419c2973296a0d4bdfe19a4f IV.

CVE-2025-9540
Markup Markdown Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-55971
Software Genérico General
4.7
MEDIUM
EPSS
0.0%
2025 2 PoCs

TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability via the UPnP MediaRenderer service (AVTransport:1). The device accepts unauthenticated SetAVTransportURI SOAP requests over TCP/16398 and attempts to retrieve externally referenced URIs, including attacker-controlled payloads. The blind SSRF allows for sending requests on behalf of the TV, which can be leveraged to probe for other internal or external services accessible by the device (e.g., 127.0.0.1:1

CVE-2025-67712
ArcGIS Web AppBuilder {Developer Edition) Web
4.7
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript execution, which limits the impact. At the time of submission, ArcGIS Web App Builder developer edition is retired and unsupported. ArcGIS Web App Builder 2.30 is not susceptible to this vulnerability.

CVE-2025-12569
Guest posting / Frontend Posting / Front Editor Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2025-28355
Software Genérico Web
4.7
MEDIUM
EPSS
0.2%
2025 2 PoCs

Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none

CVE-2025-22208
JS Jobs component for Joomla Web Database
4.7
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.

CVE-2025-9541
Markup Markdown Web Windows
4.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-0522
LikeBot Web Windows
4.7
MEDIUM
EPSS
0.1%
2025 1 PoC

The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2025-30675
Apache CloudStack Web Cloud
4.7
MEDIUM
EPSS
0.4%
2025 CWE-200 1 PoC

In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecutable' values. This allows the attacker to gain unauthorized visibility into templates and ISOs under the ROOT domain. A malicious admin can enumerate and extract metadata of templates and ISOs that belong to unrelated domains, violating isolation boundaries and potentially exposing sensitive or internal configuration details.  This vul

CVE-2025-36041
MQ Operator General
4.7
MEDIUM
EPSS
0.0%
2025 CWE-295 1 PoC

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or allow the attacker to perform unauthorized actions.

CVE-2025-4955
tarteaucitron.io Web Windows
4.7
MEDIUM
EPSS
0.3%
2025 1 PoC

The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.

CVE-2025-24240
macOS General
4.7
MEDIUM
EPSS
0.1%
2025 1 PoC

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.