5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-30401
WhatsApp Desktop for Windows Windows
6.7
MEDIUM
EPSS
0.1%
2025 1 PoC

A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp. We have not seen evidence of exploitation in the wild.

CVE-2025-55309
Software Genérico Web Windows
6.7
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the program's internal focus change handling prematurely releases the annotation object, resulting in a use-after-free vulnerability that may cause memory corruption or application crashes.

CVE-2025-32060
Infotainment system ECU General
6.7
MEDIUM
EPSS
0.0%
2025 CWE-347 2 PoCs

The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to additional vulnerabilities), then he/she is also able to load custom kernel modules to the kernel space and execute code in the kernel context. Such a flaw can lead to taking control over the entire system. First identified on Nissan Leaf ZE1 manufactured in 2020.

CVE-2025-28400
Software Genérico General
6.7
MEDIUM
EPSS
0.4%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method

CVE-2025-47228
ScriptCase Web Networking
6.7
MEDIUM
EPSS
10.0%
2025 CWE-78 1 PoC

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests.

CVE-2025-6398
AI Suite General
6.7
MEDIUM
EPSS
0.0%
2025 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the ' Security Update for for AI Suite 3 ' section on the ASUS Security Advisory for more information.

CVE-2025-1292
ChromeOS General
6.7
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.

CVE-2025-15585
fileflows Database
6.7
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploitation requires the system to use MySQL as the underlying database and could result in privilege escalation or data exfiltration.

CVE-2025-21065
Retail Mode General
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

CVE-2025-20963
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2025-44779
Software Genérico Web
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

CVE-2025-51481
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.

CVE-2025-66019
pypdf General
6.6
MEDIUM
EPSS
0.1%
2025 CWE-400 1 PoC

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

CVE-2025-70342
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe.

CVE-2025-21056
Retail Mode General
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on their own devices.

CVE-2025-24198
iOS and iPadOS General
6.6
MEDIUM
EPSS
0.1%
2025 1 PoC

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.

CVE-2025-47550
Instantio General
6.6
MEDIUM
EPSS
0.4%
2025 CWE-434 3 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell to a Web Server.This issue affects Instantio: from n/a through <= 3.3.16.

CVE-2025-55582
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dcp` and `signalc` without verifying integrity, authenticity, or permissions. An attacker with local filesystem access (via physical access, firmware modification, or debug interfaces) can replace these binaries with malicious payloads. The script executes these binaries as root in an infinite loop, leading to persistent privilege escalation and arbitrary code execution. This issue is mitigated in v1.09.02, but the product is officially End-of-Life

CVE-2025-65855
Software Genérico Web
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical access can activate OTA mode (8-second button press), create a malicious WiFi AP using the known credentials, and serve malicious firmware via unauthenticated HTTP to achieve arbitrary code execution on this safety-critical emergency signaling device.

CVE-2025-13070
CSV to SortTable Web Windows
6.6
MEDIUM
EPSS
0.1%
2025 1 PoC

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.