5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-50493
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack.

CVE-2025-54326
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in the Camera device driver can lead to a NULL pointer dereference, resulting in a denial of service.

CVE-2025-32947
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 CWE-835 1 PoC

This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities.

CVE-2025-56589
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HTML2PDF SDK thru 11.6.0. These vulnerabilities could allow an attacker to read local files on the server or make arbitrary HTTP requests to internal or external services. Both vulnerabilities could lead to the disclosure of sensitive data or potential system takeover.

CVE-2025-30762
Oracle WebLogic Server Database
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2025-27449
Endress+Hauser MEAC300-FNADE4 General
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-70758
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_validate.php. The application sends an HTTP redirect via header(Location:login.php) when a user is not authenticated but fails to call exit() afterward. This allows remote unauthenticated attackers to access protected pages.customer database.

CVE-2025-29810
Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
0.1%
2025 CWE-284 1 PoC

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

CVE-2025-22384
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 CWE-472 1 PoC

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.

CVE-2025-65513
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources.

CVE-2025-25951
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

CVE-2025-34509
Experience Manager Web ⚡ nuclei
7.5
HIGH
EPSS
18.1%
2025 CWE-798 1 PoC

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.

CVE-2025-49183
SICK Media Server Web
7.5
HIGH
EPSS
0.2%
2025 CWE-319 1 PoC

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.

CVE-2025-5920
Sharable Password Protected Posts Web
7.5
HIGH
EPSS
0.3%
2025 1 PoC

The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.

CVE-2025-15464
Fun Print Mobile General
7.5
HIGH
EPSS
0.0%
2025 CWE-926 3 PoCs

Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.

CVE-2025-12758
validator General
7.5
HIGH
EPSS
0.1%
2025 CWE-792 2 PoCs

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.

CVE-2025-27456
Endress+Hauser MEAC300-FNADE4 Windows
7.5
HIGH
EPSS
0.4%
2025 CWE-307 1 PoC

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-30567
WP01 General ⚡ nuclei
7.5
HIGH
EPSS
45.7%
2025 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Path Traversal.This issue affects WP01: from n/a through <= 2.6.2.

CVE-2025-27685
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.

CVE-2025-49182
SICK Media Server General
7.5
HIGH
EPSS
0.5%
2025 CWE-540 1 PoC

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.