5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-41705
QUINT4-UPS/24DC/24DC/5/EIP General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-523 1 PoC

An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.

CVE-2025-15441
Form Maker by 10Web Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.

CVE-2025-63892
Software Genérico Web
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument name/description causes stored cross site scripting.

CVE-2025-14973
Recipe Card Blocks Lite Web Database Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks.

CVE-2025-6515
oatpp-mcp General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-330 1 PoC

The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers with access to the oatpp-mcp server to guess future session IDs and hijack legitimate client MCP sessions, returning malicious responses from the oatpp-mcp server.

CVE-2025-2055
MapPress Maps for WordPress Web Windows
6.8
MEDIUM
EPSS
0.5%
2025 1 PoC

The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2025-27591
below General
6.8
MEDIUM
EPSS
0.1%
2025 12 PoCs

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.

CVE-2025-12351
S35 3M/5M/8M/Pinhole/Kit Camera Cloud
6.8
MEDIUM
EPSS
0.0%
2025 CWE-639 1 PoC

Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service or offering (S35 Pinhole/Kit Camera to version 2025.08.28, S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera to version 2025.08.22, S35 Thermal Camera to version 2025.08.26).

CVE-2025-60674
Software Genérico Networking
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 bytes, causing a stack overflow. An attacker with physical access or control over a USB device can exploit this vulnerability to potentially execute arbitrary code on the device.

CVE-2025-14803
NEX-Forms Web Windows
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

CVE-2025-14435
Mattermost Web
6.8
MEDIUM
EPSS
0.0%
2025 CWE-770 1 PoC

Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.

CVE-2025-9978
Jeg Kit for Elementor Web Windows
6.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting vulnerability.

CVE-2025-11984
GitLab DevOps
6.8
MEDIUM
EPSS
0.0%
2025 CWE-288 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

CVE-2025-0221
Protected Folder General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-476 2 PoCs

A vulnerability has been found in IOBit Protected Folder up to 1.3.0 and classified as problematic. This vulnerability affects the function 0x22200c in the library pffilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-6233
Mattermost General
6.8
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.

CVE-2025-9336
Armoury Crate General
6.8
MEDIUM
EPSS
0.0%
2025 CWE-121 1 PoC

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

CVE-2025-13407
Gravity Forms Web Windows
6.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

CVE-2025-5382
Server General
6.8
MEDIUM
EPSS
0.2%
2025 CWE-284 1 PoC

Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.

CVE-2025-10010
CryptoPro Secure Disk for BitLocker Windows
6.8
MEDIUM
EPSS
0.0%
2025 CWE-353 2 PoCs

The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before using BitLocker to decrypt the Windows partition. The system is located on a separate unencrypted partition which can be reached by anyone with access to the hard disk. Multiple checks are performed to validate the integrity of the Linux operating system and the CryptoPro Secure Disk application files. When files are changed an error is shown on system start. One of the checks is the Linux kernel's Integrity Measurement Architecture (IMA). It was identified that configuration