5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-2960
TEW-637AP Web
7.1
HIGH
EPSS
0.2%
2025 CWE-476 1 PoC

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the component HTTP Request Handler. The manipulation leads to null pointer dereference. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-64769
Process Optimization General
7.1
HIGH
EPSS
0.0%
2025 CWE-319 1 PoC

The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspection scenarios.

CVE-2025-1436
Limit Bio Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2025-45467
Software Genérico General
7.1
HIGH
EPSS
0.1%
2025 2 PoCs

Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.

CVE-2025-5034
wp-file-download Web Windows
7.1
HIGH
EPSS
0.2%
2025 1 PoC

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2025-63588
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2025 2 PoCs

An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.

CVE-2025-25198
mailcow-dockerized DevOps Web
7.1
HIGH
EPSS
5.8%
2025 CWE-601 2 PoCs

mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the `Host HTTP` header to generate a password reset link pointing to an attacker-controlled domain. This can lead to account takeover if a user clicks the poisoned link. Version 2025-01a contains a patch. As a workaround, deactivate the password reset functionality by clearing `Notification email sender` and `Notification email subject` under System -> Configuration -> Options -> Password Settings.

CVE-2025-11461
Frappe CRM Database
7.1
HIGH
EPSS
0.0%
2025 CWE-89 1 PoC

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.

CVE-2025-1487
WoWPth Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-61132
Software Genérico General
7.1
HIGH
EPSS
0.2%
2025 2 PoCs

A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME.

CVE-2025-32578
Coming Soon Countdown Web
7.1
HIGH
EPSS
0.2%
2025 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapro Collins Coming Soon Countdown coming-soon-countdown allows Reflected XSS.This issue affects Coming Soon Countdown: from n/a through <= 2.2.

CVE-2025-6202
DDR5 General
7.1
HIGH
EPSS
0.0%
2025 1 PoC

Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Integrity and the system's security. This issue affects DDR5: DIMMs produced from 2021-1 until 2024-12.

CVE-2025-1940
Firefox General
7.1
HIGH
EPSS
0.3%
2025 1 PoC

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.

CVE-2025-15396
Library Viewer Web Windows
7.1
HIGH
EPSS
0.0%
2025 1 PoC

The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-50491
Software Genérico Web
7.1
HIGH
EPSS
0.0%
2025 1 PoC

Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.

CVE-2025-12684
URL Shortify Web Windows
7.1
HIGH
EPSS
0.1%
2025 1 PoC

The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege users such as admins.

CVE-2025-34304
IPFire Web Networking Database
7.1
HIGH
EPSS
0.0%
2025 CWE-89 1 PoC

IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL query used when viewing OpenVPN connection logs via the CONNECTION_NAME parameter. When viewing a range of OpenVPN connection logs, the application issues an HTTP POST request to the Request-URI /cgi-bin/logs.cgi/ovpnclients.dat and inserts the value of the CONNECTION_NAME parameter directly into the WHERE clause without proper sanitization or parameterization. The unsanitized value can alter the executed query and be used to disclose sensitive infor

CVE-2025-21061
Smart Switch General
7.1
HIGH
EPSS
0.0%
2025 1 PoC

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.

CVE-2025-2959
TEW-410APB Web
7.1
HIGH
EPSS
0.2%
2025 CWE-476 2 PoCs

A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is the function sub_4019A0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-34226
OpenPLC Runtime General
7.1
HIGH
EPSS
0.2%
2025 CWE-664 1 PoC

OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime continues to operate until a restart; on restart the runtime can fail to start because of corrupted database entries, resulting in persistent denial of service requiring complete rebase of the product to recover. This vulnerability was remediated by commit 095ee09.