5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-43079
Qualys Agent Cloud
6.3
MEDIUM
EPSS
0.0%
2025 CWE-426 1 PoC

The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute paths and without sanitizing the $PATH environment. If the uninstall script is executed with elevated privileges (e.g., via sudo) in an environment where $PATH has been manipulated, an attacker with root/sudo privileges could cause malicious executables to be run in place of the intended system binaries. This behavior can be leveraged for local privilege escalation and arbitrary command execution under elevat

CVE-2025-55885
Software Genérico Web Database
6.3
MEDIUM
EPSS
0.2%
2025 1 PoC

SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php

CVE-2025-3517
Devolutions Server General
6.3
MEDIUM
EPSS
0.2%
2025 CWE-266 1 PoC

Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.

CVE-2025-66520
pdfonline.foxit.com Web Cloud
6.3
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied SVG files are not properly sanitized or validated before being inserted into the HTML structure. As a result, embedded HTML or JavaScript within a crafted SVG may execute whenever the Portfolio file list is rendered.

CVE-2025-20981
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-20965
Voice wake-up General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.

CVE-2025-20978
PENUP General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.

CVE-2025-58342
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/uapsd write operation, leading to kernel memory exhaustion.

CVE-2025-58344
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation in a /proc/driver/unifi0/conn_log_event_burst_to_us write operation, leading to kernel memory exhaustion.

CVE-2025-54409
aide General
6.2
MEDIUM
EPSS
0.0%
2025 CWE-476 1 PoC

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.

CVE-2025-20910
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

CVE-2025-60419
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.

CVE-2025-20912
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.

CVE-2025-20970
Bixby Vision General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege.

CVE-2025-21002
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.

CVE-2025-21001
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.

CVE-2025-21059
Samsung Health General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

CVE-2025-21041
Secure Folder General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.

CVE-2025-20997
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.

CVE-2025-54764
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.