2326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-9491
Windows Windows
7.0
HIGH
EPSS
0.4%
2025 CWE-451 1 PoC

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of .LNK files. Crafted data in an .LNK file can cause hazardous content in the file to be invisible to a user who inspects the file via the Windows-provided user interface. An attacker can leverage this vulnerability to

CVE-2025-5306
Pandora FMS General
7.0
HIGH
EPSS
71.3%
2025 CWE-77 1 PoC

Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778

CVE-2025-4678
Pandora ITSM General
7.0
HIGH
EPSS
1.2%
2025 CWE-77 1 PoC

Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

CVE-2025-20881
Samsung Mobile Devices General
7.0
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

CVE-2025-46817
redis Database
7.0
HIGH
EPSS
13.2%
2025 CWE-190 1 PoC

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2.

CVE-2025-3751
TIBCO ActiveMatrix BusinessWorks Database
7.0
HIGH
EPSS
0.2%
2025 CWE-89 1 PoC

The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection attack. This could lead to unauthorised access to the database and exposure of sensitive information