5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-25952
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information via a crafted API request.

CVE-2025-1013
Firefox Windows
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

CVE-2025-29154
Software Genérico General
6.5
MEDIUM
EPSS
0.8%
2025 2 PoCs

HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/ted/solicitacao_treinamento/, .galera.app/rh/metas/perspectiva_estrategica/edicao/, .galera.app/rh/cadastros/perspectivas/listagem/adc/, .galera.app/escolaridade/listagem/, .galera.app/estados_civis/cadastro/, .galera.app/nivel_hierarquico/listagem/, .galera.app/nivel_decisorio/cadastro/, .galera.app/escolaridade/cadastro/, .galera.app/nivel_decisorio/listagem/, .galera.app/rh/cadastros/perspectivas/listagem/, .galera.app/empresas_grupo/cadastro/, .galera.app

CVE-2025-54767
LPAR2RRD General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-648 1 PoC

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

CVE-2025-13683
Server Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

CVE-2025-35021
CPX Networking
6.5
MEDIUM
EPSS
0.1%
2025 CWE-1188 2 PoCs

By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth attempt, and from there, relay connections.

CVE-2025-45619
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function

CVE-2025-3028
Firefox Web
6.5
MEDIUM
EPSS
0.7%
2025 1 PoC

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

CVE-2025-54335
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU Driver.

CVE-2025-5273
mcp-markdownify-server General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-552 1 PoC

All versions of the package mcp-markdownify-server are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.

CVE-2025-43372
iOS and iPadOS General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

CVE-2025-58580
Enterprise Analytics Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-117 1 PoC

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.

CVE-2025-46000
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVE-2025-3111
GitLab DevOps
6.5
MEDIUM
EPSS
0.5%
2025 CWE-770 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

CVE-2025-65427
Software Genérico Web Networking
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

CVE-2025-53771
Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
39.6%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-60876
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).

CVE-2025-59956
agentapi Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-350 2 PoCs

AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API. This allows for the unauthorized exfiltration of sensitive user data, specifically local message history, which can include secret keys, file system contents, and intellectual property the user was working on locally. This issue is fixed in version 0.4.0.

CVE-2025-0435
Chrome General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

CVE-2025-22921
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.