5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-22384
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 CWE-472 1 PoC

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.

CVE-2025-65513
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources.

CVE-2025-25951
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

CVE-2025-49183
SICK Media Server Web
7.5
HIGH
EPSS
0.2%
2025 CWE-319 1 PoC

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.

CVE-2025-5920
Sharable Password Protected Posts Web
7.5
HIGH
EPSS
0.3%
2025 1 PoC

The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.

CVE-2025-27685
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.

CVE-2025-61100
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.

CVE-2025-59375
libexpat General
7.5
HIGH
EPSS
0.1%
2025 CWE-770 1 PoC

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

CVE-2025-49494
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 5123. Mishandling of an 5G NRMM packet leads to a Denial of Service.

CVE-2025-46709
Graphics DDK General
7.5
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kernel exception.

CVE-2025-67015
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

CVE-2025-65857
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

CVE-2025-3194
bigint-buffer General
7.5
HIGH
EPSS
0.4%
2025 CWE-120 1 PoC

Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.

CVE-2025-12758
validator General
7.5
HIGH
EPSS
0.1%
2025 CWE-792 2 PoCs

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.

CVE-2025-59049
mockoon Web Cloud ⚡ nuclei
7.5
HIGH
EPSS
1.9%
2025 CWE-73 0 PoCs

Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach presented in the documentation page, where the server filename is generated via templating features from user input is vulnerable to Path Traversal and LFI, allowing an attacker to get any file in the mock server filesystem. The issue may be particularly relevant in cloud hosted server instances. Version 9.2.0 fixes the issue.

CVE-2025-29448
Software Genérico General
7.5
HIGH
EPSS
0.5%
2025 1 PoC

Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.

CVE-2025-41703
QUINT4-UPS/24DC/24DC/5/EIP General
7.5
HIGH
EPSS
0.2%
2025 CWE-306 1 PoC

An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command.

CVE-2025-38501
Linux Windows
7.5
HIGH
EPSS
0.1%
2025 1 PoC

In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client connections. This patch limit repeated connections from clients with the same IP.

CVE-2025-56223
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.

CVE-2025-43864
react-router Networking
7.5
HIGH
EPSS
0.4%
2025 CWE-755 1 PoC

React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system is in place, this allows the response containing the error to be cached, resulting in a cache poisoning that strongly impacts the availability of the application. This issue has been patched in version 7.5.2.