5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-52357
Software Genérico Web Networking
4.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firmware V2.2.14), allowing an authenticated attacker to execute arbitrary JavaScript code in the context of the router s web interface. The vulnerability is triggered via user-supplied input in the ping form field, which fails to sanitize special characters. This can be exploited to hijack sessions or escalate privileges through social engineering or browser-based attacks.

CVE-2025-3951
WP-Optimize Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.

CVE-2025-43929
kitty General
4.1
MEDIUM
EPSS
0.1%
2025 CWE-346 1 PoC

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

CVE-2025-8865
YugabyteDB General
4.1
MEDIUM
EPSS
0.0%
2025 CWE-476 1 PoC

The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.

CVE-2025-21037
SamsungNotes General
4.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for triggering this vulnerability.

CVE-2025-64641
Mattermost General
4.1
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts

CVE-2025-20940
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.

CVE-2025-54310
qBittorrent General
4.0
MEDIUM
EPSS
0.1%
2025 CWE-669 1 PoC

qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.

CVE-2025-20992
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.

CVE-2025-20950
SamsungNotes General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.

CVE-2025-20960
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

CVE-2025-21034
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

CVE-2025-20980
libsavscmn General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

CVE-2025-20896
EasySetup General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information.

CVE-2025-0239
Firefox General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVE-2025-21067
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

CVE-2025-8285
Mattermost Confluence Plugin Web
4.0
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.

CVE-2025-21052
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

CVE-2025-20909
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-21033
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.