5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-64405
Apache OpenOffice Web
7.5
HIGH
EPSS
0.2%
2025 CWE-862 1 PoC

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, Calc spreadsheet containing DDE links to external files would load the contents of those files without prompting the user for permission to do so. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.

CVE-2025-48707
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing.

CVE-2025-14874
nodemailer General
7.5
HIGH
EPSS
0.2%
2025 CWE-703 1 PoC

A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.

CVE-2025-11149
node-static Web
7.5
HIGH
EPSS
0.0%
2025 CWE-400 3 PoCs

This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.

CVE-2025-32947
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 CWE-835 1 PoC

This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities.

CVE-2025-30762
Oracle WebLogic Server Database
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2025-25685
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a samba share.

CVE-2025-14894
Livewire Filemanager Web
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.

CVE-2025-54323
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. Improper debug printing leads to information leakage.

CVE-2025-13654
Duc General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a condition can evaluate to true due to underflow, allowing an out-of-bounds read.

CVE-2025-8021
files-bucket-server General
7.5
HIGH
EPSS
0.7%
2025 CWE-22 1 PoC

All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files outside of the intended directory.

CVE-2025-51868
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.

CVE-2025-47227
ScriptCase Web
7.5
HIGH
EPSS
3.4%
2025 CWE-684 2 PoCs

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

CVE-2025-27223
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
5.5%
2025 1 PoC

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.

CVE-2025-25475
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.

CVE-2025-25758
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

CVE-2025-3193
algoliasearch-helper Web
7.5
HIGH
EPSS
0.1%
2025 CWE-1321 2 PoCs

Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected into the user-supplied search parameter may be exeucted. This is related to but distinct from the issue reported in [CVE-2021-23433](https://security.snyk.io/vuln/SNYK-JS-ALGOLIASEARCHHELPER-1570421). **NOTE:** This vulnerability is not exploitable in the default configuration of

CVE-2025-58726
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
0.1%
2025 CWE-284 2 PoCs

Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

CVE-2025-8014
GitLab DevOps
7.5
HIGH
EPSS
0.1%
2025 CWE-770 1 PoC

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

CVE-2025-51628
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated attackers to read confidential documents via the DocumentoId parameter.