5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-25468
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.

CVE-2025-41395
Mattermost General
6.5
MEDIUM
EPSS
0.1%
2025 CWE-1287 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.

CVE-2025-52168
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system.

CVE-2025-26055
Software Genérico General
6.5
MEDIUM
EPSS
0.8%
2025 1 PoC

An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.

CVE-2025-23167
node Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.

CVE-2025-47222
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded in the application or not to the clientside.

CVE-2025-28367
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
12.7%
2025 0 PoCs

mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.

CVE-2025-65407
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream.

CVE-2025-55341
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad.

CVE-2025-20072
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2025 CWE-704 1 PoC

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.

CVE-2025-11705
Anti-Malware Security and Brute-Force Firewall Web Networking Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to a missing capability check combined with an information exposure in several GOTMLS_* AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2025-32815
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
27.6%
2025 0 PoCs

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

CVE-2025-50847
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request.

CVE-2025-5983
Meta Tag Manager Web Windows
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

The Meta Tag Manager WordPress plugin before 3.3 does not restrict which roles can create http-equiv refresh meta tags.

CVE-2025-26784
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 2 PoCs

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

CVE-2025-2522
C300 PCNT02 General
6.5
MEDIUM
EPSS
0.3%
2025 CWE-226 1 PoC

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect system behavior. Honeywell also recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1.  The affected Experion PKS products are C300, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The E

CVE-2025-51627
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator.

CVE-2025-55311
Software Genérico Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.

CVE-2025-50043
Code Engine Web
6.5
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Code Engine code-engine allows Stored XSS.This issue affects Code Engine: from n/a through <= 0.3.2.

CVE-2025-41678
mbNET.mini Database
6.5
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.