5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-43714
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers.

CVE-2025-60672
Software Genérico Web Networking
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands executed via twsystem(). An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted HTTP request, leading to arbitrary command execution on the device.

CVE-2025-45663
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

CVE-2025-56162
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modify database data, including dumping admin password hashes; (b) write web-shell files or invoke xp_cmdshell, leading to remote code execution on servers configured with sufficient DB privileges.

CVE-2025-47906
os/exec General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

CVE-2025-9076
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

CVE-2025-0441
Chrome General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information from the system via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-54603
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

CVE-2025-55629
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allow attackers to arbitrarily change other users' passwords via manipulation of the userName value.

CVE-2025-51089
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow.

CVE-2025-21088
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-704 1 PoC

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.

CVE-2025-59214
Windows 10 Version 1507 Windows
6.5
MEDIUM
EPSS
0.1%
2025 CWE-200 3 PoCs

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-8994
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from th

CVE-2025-65784
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.

CVE-2025-63716
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operations. The application lacks CSRF protection mechanisms such as anti-CSRF tokens or same-origin verification for critical endpoints.

CVE-2025-46206
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 2 PoCs

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion

CVE-2025-10540
iMonitor EAM General
6.5
MEDIUM
EPSS
0.0%
2025 CWE-319 2 PoCs

iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credentials, keylogger data, and personally identifiable information) and tamper with traffic. This allows both unauthorized disclosure and modification of data, including issuing arbitrary commands to client agents.

CVE-2025-58364
cups General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-20 1 PoC

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups & cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was n

CVE-2025-44895
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.

CVE-2025-45746
ZKBio CVSecurity General
6.5
MEDIUM
EPSS
0.9%
2025 CWE-321 1 PoC

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and because access to the service console does not result in login access or data access in the context of the application software platform.