5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-63261
Software Genérico Cloud
7.8
HIGH
EPSS
0.1%
2025 1 PoC

AWStats 8.0 is vulnerable to Command Injection via the open function

CVE-2025-24379
Unity General
7.8
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

CVE-2025-0478
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform, altering their behaviour.

CVE-2025-30464
macOS General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVE-2025-50675
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 2 PoCs

GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory is accessible with full read, write, and execute permissions for all users, allowing unprivileged users to manipulate files within the directory, including executable files like GPMAW3.exe, Fragment.exe, and the uninstaller GPsetup64_17028.exe. An attacker with user-level access can exploit this misconfiguration by replacing or modifying the uninstaller (GPsetup64_17028.exe) with a malicious version. While the application itself runs in the user's

CVE-2025-48549
Android General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-23386
openSUSE Tumbleweed General
7.8
HIGH
EPSS
0.1%
2025 CWE-276 1 PoC

A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1.

CVE-2025-24985
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
1.7%
2025 CWE-190 3 PoCs

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

CVE-2025-66495
Foxit PDF Reader Web Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

CVE-2025-68973
GnuPG General
7.8
HIGH
EPSS
0.0%
2025 CWE-675 2 PoCs

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

CVE-2025-43576
Acrobat Reader General
7.8
HIGH
EPSS
0.2%
2025 CWE-416 1 PoC

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2025-0015
Valhall GPU Kernel Driver General
7.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to make improper GPU processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r48p0 through r49p1, from r50p0 through r52p0; Arm 5th Gen GPU Architecture Kernel Driver: from r48p0 through r49p1, from r50p0 through r52p0.

CVE-2025-61156
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL.

CVE-2025-26859
RemoteView PC Application Console General
7.8
HIGH
EPSS
0.0%
2025 CWE-427 1 PoC

RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

CVE-2025-69875
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local attacker to place files in high-privilege locations, potentially leading to privilege escalation.

CVE-2025-55230
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-822 1 PoC

Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.

CVE-2025-24267
macOS General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVE-2025-24377
Unity General
7.8
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.

CVE-2025-48586
Android General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-54257
Acrobat Reader General
7.8
HIGH
EPSS
0.0%
2025 CWE-416 1 PoC

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.