5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-59462
TLOC100-100 all Firmware versions General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-248 1 PoC

An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.

CVE-2025-21574
MySQL Cluster Database
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2025-49706
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
75.0%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-30446
macOS General
6.5
MEDIUM
EPSS
0.5%
2025 1 PoC

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app with root privileges may be able to modify the contents of system files.

CVE-2025-44892
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.

CVE-2025-24194
iOS and iPadOS General
6.5
MEDIUM
EPSS
0.4%
2025 3 PoCs

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may result in the disclosure of process memory.

CVE-2025-51859
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability in Chaindesk thru 2025-05-26 in its agent chat component. An attacker can achieve arbitrary client-side script execution by crafting an AI agent whose system prompt instructs the underlying Large Language Model (LLM) to embed malicious script payloads (e.g., SVG-based XSS) into its chat responses. When a user interacts with such a malicious agent or accesses a direct link to a conversation containing an XSS payload, the script executes in the user's browser. Successful exploitation can lead to the theft of sensitive information, such as JWT sessi

CVE-2025-66911
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks.

CVE-2025-45317
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted archive.

CVE-2025-52166
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator and access sensitive components and information.

CVE-2025-51969
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL statement.

CVE-2025-2745
PI Web API Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.

CVE-2025-23096
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.

CVE-2025-51403
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.

CVE-2025-27457
Endress+Hauser MEAC300-FNADE4 General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-319 1 PoC

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.

CVE-2025-15574
Pocket WiFi 3.0 Cloud
6.5
MEDIUM
EPSS
0.0%
2025 CWE-330 1 PoC

When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the knowledge of the registration numbers can connect to the MQTT server and impersonate the dongle / inverters.

CVE-2025-60682
Software Genérico Web Networking Cloud
6.5
MEDIUM
EPSS
0.7%
2025 1 PoC

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed via system() without any sanitization or escaping. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device.

CVE-2025-9544
Doppler Forms Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capabilities or using a nonce. As a result, any authenticated user — including those with the Subscriber role — can install and activate additional Doppler Forms WordPress plugin through 2.5.1 (limited to those whitelisted by the main Doppler Forms WordPress plugin through 2.5.1).

CVE-2025-50083
MySQL Server Database
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).