5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-53771
Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
39.6%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-65408
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file.

CVE-2025-60540
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF).

CVE-2025-22921
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

CVE-2025-3472
Ocean Extra Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
17.3%
2025 CWE-94 0 PoCs

The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.

CVE-2025-25474
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.

CVE-2025-12573
Bookingor Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, allowing low-privileged users to delete Bookingor WordPress plugin through 1.0.12 data.

CVE-2025-41678
mbNET.mini Database
6.5
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.

CVE-2025-20362
🔥 KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Networking ⚡ nuclei
6.5
MEDIUM
EPSS
44.1%
2025 CWE-862 0 PoCs

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisc

CVE-2025-25478
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.

CVE-2025-27803
cPH2 / cPP2 charging stations General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-306 2 PoCs

The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.

CVE-2025-20630
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-1287 1 PoC

Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.

CVE-2025-65288
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long hostnames from LAN hosts without proper length validation. The affected code performs unchecked copies/concatenations into fixed-size buffers. A crafted long hostname can overflow the buffer, cause a crash (DoS) and potentially enabling remote code execution.

CVE-2025-29267
Software Genérico Database
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to obtain a sensitive information via the cid parameter in the GET request.

CVE-2025-64402
Apache OpenOffice Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "OLE objects" linked to external files would load the contents of those files without prompting the user for permission to do so. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.

CVE-2025-61224
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter

CVE-2025-48414
cPH2 / cPP2 charging stations General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-798 2 PoCs

There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are likely intended for debugging during development and provides an additional attack surface.

CVE-2025-59686
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.

CVE-2025-60673
Software Genérico Web Networking
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi is stored in NVRAM and later used by librcm.so to construct iptables commands executed via twsystem(). An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted HTTP request, leading to arbitrary command execution on the device.

CVE-2025-21088
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-704 1 PoC

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.