5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-24948
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.

CVE-2025-58591
Baggage Analytics General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information.

CVE-2025-48417
cPH2 / cPP2 charging stations General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-321 2 PoCs

The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware and are shipped with the update files. An attacker can use the private key to perform man-in-the-middle attacks against users of the admin interface. The files are located in /etc/ssl (e.g. salia.local.crt, salia.local.key and salia.local.pem). There is no option to upload/configure custom TLS certificates.

CVE-2025-50234
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2025 2 PoCs

MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function, which utilizes a hard-coded key Mc_Encryption_Key (bD2voYwPpNuJ7B8), defined in the db.php file. The decrypted URL is passed to the geturl() method, which uses cURL to make a request to the URL without proper security checks. An attacker can craft a malicious encrypted pic parameter, which, when decrypted, points to internal addresses or local file paths (such as http://127.0.

CVE-2025-65127
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device configuration data, including plaintext credentials, without authentication or an existing session.

CVE-2025-67278
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

CVE-2025-60700
Software Genérico Networking
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later retrieved in the `DMZ_run` function of `librcm.so` using `nvram_safe_get` and concatenated into `iptables` shell commands executed via `twsystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device thr

CVE-2025-63718
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient_schedule.php endpoint. The appointmentID parameter is not properly sanitized, allowing attackers to execute arbitrary SQL commands.

CVE-2025-46002
Software Genérico Web
6.5
MEDIUM
EPSS
1.2%
2025 2 PoCs

An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.

CVE-2025-32100
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. A programming mistake for buffer copy leads to out-of-bounds writes via malformed ROHC packets.

CVE-2025-48414
cPH2 / cPP2 charging stations General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-798 2 PoCs

There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during development and provides an additional attack surface.

CVE-2025-27450
Endress+Hauser MEAC300-FNADE4 Web
6.5
MEDIUM
EPSS
0.2%
2025 CWE-614 1 PoC

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.

CVE-2025-51458
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1.editor_sql_run, editor_chart_run, and datasource.rdbms.base.query_ex.

CVE-2025-65427
Software Genérico Web Networking
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

CVE-2025-1718
Relion 670/650 and SAM600-IO General
6.5
MEDIUM
EPSS
0.3%
2025 CWE-754 1 PoC

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk space management.

CVE-2025-0435
Chrome General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

CVE-2025-60687
Software Genérico Networking
6.5
MEDIUM
EPSS
4.0%
2025 1 PoC

An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter from a web request and verifies only that it is 15 characters long. The parameter is then directly inserted into a system command using sprintf() and executed with system(). Maliciously crafted IMEI input can execute arbitrary commands on the router without authentication.

CVE-2025-20086
Mattermost General
6.5
MEDIUM
EPSS
0.4%
2025 CWE-1287 1 PoC

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

CVE-2025-58587
Baggage Analytics General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-307 1 PoC

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials.

CVE-2025-61540
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.