5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-24170
macOS General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVE-2025-22447
RemoteView Agent (for Windows) Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-276 1 PoC

Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.

CVE-2025-6218
🔥 KEV WinRAR General
7.8
HIGH
EPSS
6.6%
2025 CWE-22 5 PoCs

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.

CVE-2025-61156
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL.

CVE-2025-26859
RemoteView PC Application Console General
7.8
HIGH
EPSS
0.0%
2025 CWE-427 1 PoC

RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

CVE-2025-69875
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local attacker to place files in high-privilege locations, potentially leading to privilege escalation.

CVE-2025-43729
ThinOS 10 General
7.8
HIGH
EPSS
0.0%
2025 CWE-732 1 PoC

Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A local low-privileged attacker could potentially exploit this vulnerability leading to Elevation of Privileges and Unauthorized Access.

CVE-2025-24985
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
1.7%
2025 CWE-190 3 PoCs

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

CVE-2025-22458
Endpoint Manager General
7.8
HIGH
EPSS
0.2%
2025 CWE-427 1 PoC

DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

CVE-2025-47176
Microsoft 365 Apps for Enterprise General
7.8
HIGH
EPSS
1.2%
2025 CWE-35 1 PoC

'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.

CVE-2025-30400
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.8%
2025 CWE-416 1 PoC

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2025-9326
PDF Reader General
7.8
HIGH
EPSS
0.1%
2025 CWE-125 1 PoC

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in

CVE-2025-41244
🔥 KEV VCF operations General
7.8
HIGH
EPSS
0.6%
2025 CWE-267 3 PoCs

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVE-2025-43950
Software Genérico General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which is then loaded by the application instead of the legitimate DLL. This causes the malicious DLL to load with the same privileges as the application, thus causing a privilege escalation.

CVE-2025-0285
Migrate OS to SSD General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.

CVE-2025-54100
Windows 10 Version 1607 Windows
7.8
HIGH
EPSS
0.2%
2025 CWE-77 2 PoCs

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.

CVE-2025-54257
Acrobat Reader General
7.8
HIGH
EPSS
0.0%
2025 CWE-416 1 PoC

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.

CVE-2025-0835
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.

CVE-2025-55230
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-822 1 PoC

Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.

CVE-2025-24267
macOS General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.