5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-24113
Safari General
4.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.

CVE-2025-14350
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the channel_mentions property in the API response. Mattermost Advisory ID: MMSA-2025-00563

CVE-2025-30179
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.

CVE-2025-7000
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2025 CWE-201 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVE-2025-15473
Timetics Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.

CVE-2025-27455
Endress+Hauser MEAC300-FNADE4 General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others to take control of their computer while clicking on seemingly innocuous objects.

CVE-2025-41443
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint

CVE-2025-13765
Server General
4.3
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

CVE-2025-6195
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2025 CWE-425 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.

CVE-2025-4580
File Provider Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-12189
Bread & Butter: AI-Powered Lead Intelligence Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 2 PoCs

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.11.1374. This is due to missing or incorrect nonce validation on the uploadImage() function. This makes it possible for unauthenticated attackers to upload arbitrary files that make remote code execution possible via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-48025
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 2 PoCs

In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000, there is an improper access control vulnerability related to a log file.

CVE-2025-26849
Docusnap Networking
4.3
MEDIUM
EPSS
0.1%
2025 CWE-1394 1 PoC

There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain sensitive information such as firewall rules.

CVE-2025-13794
Auto Featured Image (Auto Post Thumbnail) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete or generate featured images on posts they do not own.

CVE-2025-13767
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.

CVE-2025-1362
URL Shortener | Conversion Tracking | AB Testing | WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks

CVE-2025-21014
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-5730
Contact Form Plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVE-2025-21055
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

CVE-2025-22828
Apache CloudStack Web Cloud
4.3
MEDIUM
EPSS
18.4%
2025 CWE-200 1 PoC

CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add comments (annotations) to such resources.  An attacker with a user-account and access or prior knowledge of resource UUIDs may exploit this issue to read contents of the comments (annotations) or add malicious comments (annotations) to such resources.  This may cause potential loss of confidentiality of CloudStack environm