5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-56514
Software Genérico Web
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malicious SVG files are rendered by other users.

CVE-2025-36730
Windsurf General
4.6
MEDIUM
EPSS
0.0%
2025 CWE-1427 1 PoC

A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.

CVE-2025-60917
Software Genérico Web
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the color parameter.

CVE-2025-27441
Zoom Workplace Apps General
4.6
MEDIUM
EPSS
0.4%
2025 CWE-79 1 PoC

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVE-2025-56689
Software Genérico General
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response. NOTE: this is disputed by the Supplier because, by design, the product successfully authenticates a client that possesses a cookie whose validity time interval includes the current time, and thus authentication after any type of "interception" is not a violation of the security mod

CVE-2025-21035
Samsung Calendar General
4.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles.

CVE-2025-48074
openexr General
4.6
MEDIUM
EPSS
0.0%
2025 CWE-770 1 PoC

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.

CVE-2025-27801
Episerver Content Management System (CMS) Web
4.6
MEDIUM
EPSS
0.1%
2025 CWE-79 2 PoCs

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. ContentReference properties, which could be used in the "Edit" section of the CMS, offered an upload functionality for documents. These documents could later be used as displayed content on the page. It was possible to upload SVG files that include malicious JavaScript code that would be executed if a user visited the direct URL of the preview image. Attacke

CVE-2025-59096
Kaba exos 9300 General
4.6
MEDIUM
EPSS
0.0%
2025 CWE-798 2 PoCs

The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.

CVE-2025-30439
iOS and iPadOS General
4.6
MEDIUM
EPSS
0.1%
2025 2 PoCs

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.

CVE-2025-69893
Software Genérico General
4.6
MEDIUM
EPSS
0.1%
2025 1 PoC

A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which induce non-constant time execution and specific branch patterns for word searching. An attacker with physical access during the initial setup phase can collect a single side-channel trace. By utilizing profiling-based Deep Learning Side-Channel Analysis (DL-SCA), the attacker can recover the mnemonic code and subsequently

CVE-2025-47814
PSPP General
4.5
MEDIUM
EPSS
0.2%
2025 CWE-122 1 PoC

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.

CVE-2025-3503
WP Maps Web Windows
4.5
MEDIUM
EPSS
0.2%
2025 1 PoC

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-26791
DOMPurify Web
4.5
MEDIUM
EPSS
0.1%
2025 CWE-79 2 PoCs

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

CVE-2025-46646
Ghostscript General
4.5
MEDIUM
EPSS
0.1%
2025 CWE-24 1 PoC

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

CVE-2025-63712
Software Genérico Web
4.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection.

CVE-2025-47815
PSPP General
4.5
MEDIUM
EPSS
0.2%
2025 CWE-122 1 PoC

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.

CVE-2025-20994
Samsung Internet General
4.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access read and write arbitrary files.

CVE-2025-9913
Baggage Analytics Web
4.5
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

CVE-2025-10124
Booking Manager Web Windows
4.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.