5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-8582
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-20 1 PoC

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-41254
Spring Framework Web
4.3
MEDIUM
EPSS
0.1%
2025 CWE-352 2 PoCs

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: * 6.2.0 - 6.2.11 * 6.1.0 - 6.1.23 * 6.0.x - 6.0.29 * 5.3.0 - 5.3.45 * Older, unsupported versions are also affected. MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix versionAvailability6.2.x6.2.12OSS6.1.x6.1.24 Commercial https://enterprise.spring.io/ 6.0.xN/A Out of support https://spring.io/projects/spring-framework#support 5.3.x5.

CVE-2025-27581
BRICS General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-425 1 PoC

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.

CVE-2025-59687
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization.

CVE-2025-3227
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel.

CVE-2025-52923
aTrust General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-732 1 PoC

Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.

CVE-2025-4664
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2025-24216
Safari General
4.3
MEDIUM
EPSS
0.1%
2025 3 PoCs

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2025-46708
Graphics DDK General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.

CVE-2025-4976
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2025 CWE-213 1 PoC

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

CVE-2025-30427
Safari General
4.3
MEDIUM
EPSS
0.2%
2025 3 PoCs

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2025-54320
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.

CVE-2025-47870
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.

CVE-2025-11519
Optimole – Optimize Images in Real Time Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-639 1 PoC

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the /wp-json/optml/v1/move_image REST API endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to offload media that doesn't belong to them.

CVE-2025-2942
Order Delivery Date Web Windows
4.3
MEDIUM
EPSS
0.3%
2025 1 PoC

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

CVE-2025-49192
SICK Field Analytics General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while clicking on seemingly innocuous objects.

CVE-2025-21016
Samsung Mobile Devices Web
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allows local attackers to use the privileged APIs.

CVE-2025-1922
Chrome General
4.3
MEDIUM
EPSS
0.3%
2025 CWE-451 1 PoC

Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-1762
Event Tickets with Ticket Scanner Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-21030
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.