5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-13029
Knowband Mobile App Builder Web Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users.

CVE-2025-21181
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
13.6%
2025 CWE-400 2 PoCs

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2025-64335
suricata General
7.5
HIGH
EPSS
0.1%
2025 CWE-476 2 PoCs

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

CVE-2025-63422
Software Genérico Networking
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request.

CVE-2025-70148
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).

CVE-2025-35966
Comdb2 Database
7.5
HIGH
EPSS
0.1%
2025 CWE-476 2 PoCs

A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2 8.1. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this vulnerability.

CVE-2025-1025
cockpit-hq/cockpit General ⚡ nuclei
7.5
HIGH
EPSS
6.0%
2025 CWE-434 1 PoC

Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.

CVE-2025-25163
Plugin A/B Image Optimizer General
7.5
HIGH
EPSS
26.4%
2025 CWE-22 2 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer images-optimizer allows Path Traversal.This issue affects Plugin A/B Image Optimizer: from n/a through <= 3.3.

CVE-2025-37097
Insight Remote Support General
7.5
HIGH
EPSS
0.5%
2025 1 PoC

A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service

CVE-2025-1931
Firefox General
7.5
HIGH
EPSS
0.4%
2025 1 PoC

It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-10497
GitLab DevOps
7.5
HIGH
EPSS
0.1%
2025 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

CVE-2025-58180
OctoPrint General
7.5
HIGH
EPSS
1.6%
2025 CWE-78 1 PoC

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution if said filename becomes included in a command defined in a system event handler and said event gets triggered. If no event handlers executing system commands with uploaded filenames as parameters have been configured, this vulnerability does not have an impact. The vulnerability is patched in version 1.11.3. As a work

CVE-2025-12726
Chrome Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

CVE-2025-65176
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is installed and receiving a "STATUS_LOGON_FAILURE" error, the agent will retrieve every user token on the machine and repeatedly attempt to access the network share while impersonating them. The exploitation of this vulnerability can allow an unprivileged attacker with access to the affected system to perform NTLM relay attacks.

CVE-2025-63205
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. NOTE: the Supplier disagrees that 6.5.0-9 is affected, and instead reports that 5.6.0-3 and earlier are affected, and 5.6.0-4 (2020-09-21) and later are fixed.

CVE-2025-61104
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVE-2025-67015
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

CVE-2025-30471
iOS and iPadOS General
7.5
HIGH
EPSS
0.5%
2025 4 PoCs

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A remote user may be able to cause a denial-of-service.

CVE-2025-26785
Software Genérico General
7.5
HIGH
EPSS
0.4%
2025 2 PoCs

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

CVE-2025-60574
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.