5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-0442
Chrome General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-50420
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

CVE-2025-24949
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2025 1 PoC

In JotUrl 2.0, is possible to bypass security requirements during the password change process.

CVE-2025-15033
WooCommerce General
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in 8.1.3. It does not affect WooCommerce 8.0 or earlier.

CVE-2025-12685
WPBookit Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.

CVE-2025-52078
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2025 1 PoC

File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint.

CVE-2025-51403
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2025 1 PoC

A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.

CVE-2025-50154
Windows 10 Version 1507 Windows
6.5
MEDIUM
EPSS
24.3%
2025 CWE-200 4 PoCs

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-51459
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2025 1 PoC

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hub._sanitize_filename and plugins_util.scan_plugins.

CVE-2025-32809
InQuizitive Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.

CVE-2025-61765
python-socketio Database
6.4
MEDIUM
EPSS
0.7%
2025 CWE-502 1 PoC

python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module

CVE-2025-32369
Xperience Web
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 2 PoCs

Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.

CVE-2025-20943
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.

CVE-2025-0845
DesignThemes Core Features Web Windows
6.4
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-11361
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-918 1 PoC

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

CVE-2025-12045
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the category and tag 'name' parameters in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-30432
iOS and iPadOS General
6.4
MEDIUM
EPSS
0.1%
2025 4 PoCs

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.

CVE-2025-4611
Slim SEO – A Fast & Automated SEO Plugin For WordPress Web Windows
6.4
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2025-59712
Snipe-IT Web
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Snipe-IT before 8.1.18 allows XSS.

CVE-2025-14040
Automotive Car Dealership Business WordPress Theme Web Windows
6.4
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Call to Action' custom fields in all versions up to, and including, 13.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'action_text', 'action_button_text', 'action_link', and 'action_class' custom fields. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.