5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-4690
AngularJS Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-1333 4 PoCs

A regular expression used by AngularJS'  linky https://docs.angularjs.org/api/ngSanitize/filter/linky  filter to detect URLs in input text is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can cause a Regular expression Denial of Service (ReDoS) https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS  attack on the application. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://

CVE-2025-47813
🔥 KEV Wing FTP Server General ⚡ nuclei
4.3
MEDIUM
EPSS
25.0%
2025 CWE-209 2 PoCs

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CVE-2025-4476
Software Genérico Web
4.3
MEDIUM
EPSS
0.3%
2025 CWE-476 1 PoC

A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requir

CVE-2025-65647
Software Genérico Web
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.

CVE-2025-36599
PowerFlex Manager VM General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-532 1 PoC

Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.

CVE-2025-49164
VIP1113 Networking
4.3
MEDIUM
EPSS
0.1%
2025 CWE-321 1 PoC

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a485f49a8a7d0c8b0fdc9f51ced50f2530668a.

CVE-2025-59463
TLOC100-100 all Firmware versions General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-833 1 PoC

An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.

CVE-2025-1923
Chrome General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

CVE-2025-2404
STOYS Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS).This issue affects STOYS: from 2 before 20250916.

CVE-2025-8595
Zakra Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings.

CVE-2025-9914
Baggage Analytics General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-288 1 PoC

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.

CVE-2025-62190
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link

CVE-2025-20129
Cisco SocialMiner Web Networking
4.3
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting

CVE-2025-50340
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized to use the specified sender identity, resulting in unauthorized message delivery as another user. This can lead to impersonation, phishing, or unauthorized communication within the system. NOTE: this is disputed by the Supplier because the only effective way to prevent this sender

CVE-2025-25274
Mattermost General
4.3
MEDIUM
EPSS
0.5%
2025 CWE-863 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.

CVE-2025-10700
Ally – Web Accessibility & Usability Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable unfiltered file upload and add svg files to the upload list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-1711
Endress+Hauser MEAC300-FNADE4 General
4.3
MEDIUM
EPSS
0.3%
2025 CWE-1392 1 PoC

Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.

CVE-2025-8682
Newsup Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the ansar-import plugin.

CVE-2025-46549
yeswiki Web ⚡ nuclei
4.3
MEDIUM
EPSS
0.4%
2025 CWE-79 0 PoCs

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.

CVE-2025-9202
ColorMag Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin.