5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-31184
Safari General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network.

CVE-2025-29625
Software Genérico General
7.8
HIGH
EPSS
0.2%
2025 1 PoC

A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overly long environment variable passed to FileOpen function.

CVE-2025-32706
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
1.3%
2025 CWE-20 2 PoCs

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-24864
RemoteView Agent (for Windows) Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-276 1 PoC

Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.

CVE-2025-1683
1E Client Windows
7.8
HIGH
EPSS
0.2%
2025 CWE-59 1 PoC

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.

CVE-2025-24139
macOS General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Ventura 13.7.5. Parsing a maliciously crafted file may lead to an unexpected app termination.

CVE-2025-34489
MailEssentials General
7.8
HIGH
EPSS
0.1%
2025 CWE-502 1 PoC

GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by sending a crafted serialized payload to a .NET Remoting Service.

CVE-2025-50777
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in plaintext, enabling further compromise of the network and connected systems.

CVE-2025-4275
InsydeH2O General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.

CVE-2025-53773
Microsoft Visual Studio 2022 version 17.14 General
7.8
HIGH
EPSS
4.6%
2025 CWE-77 2 PoCs

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

CVE-2025-60710
🔥 KEV Windows 11 Version 24H2 Windows
7.8
HIGH
EPSS
29.7%
2025 CWE-59 2 PoCs

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2025-55314
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

CVE-2025-55312
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

CVE-2025-25179
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.

CVE-2025-23383
Unity General
7.8
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

CVE-2025-21204
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
7.3%
2025 CWE-59 2 PoCs

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVE-2025-56124
Software Genérico General
7.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-24228
macOS General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to execute arbitrary code with kernel privileges.

CVE-2025-25178
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2025 CWE-1284 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.