5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-13031
WPeMatico RSS Feed Fetcher Web Windows
5.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2025-21032
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.

CVE-2025-15363
Get Use APIs Web Windows
5.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks under certain server configurations.

CVE-2025-9824
Mautic General
5.9
MEDIUM
EPSS
0.1%
2025 CWE-204 1 PoC

ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when: * A valid username was provided (password hashing occurred) * An invalid username was provided (no password hashing occurre

CVE-2025-47416
TOUCHSCREEN x70 General
5.9
MEDIUM
EPSS
0.1%
2025 CWE-697 1 PoC

A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets prioritized by the ConsoleFindCommandMatchList. A third-party researcher discovered that the ConsoleFindCommandMatchList enumerates the /dev/shm/symproc/c directory in alphabetical order to identify console commands. Permission levels are inferred from the integer values present in each command's file name.  Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061  Fixed Fir

CVE-2025-32407
Software Genérico Web
5.9
MEDIUM
EPSS
0.0%
2025 1 PoC

Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfiguration in the way the browser validates the identity of the server. It negates the use of HTTPS as a secure channel, allowing for Man-in-the-Middle attacks, stealing sensitive information or modifying incoming and outgoing traffic. NOTE: This vulnerability is in an end-of-life product that is no longer maintained by the vendor.

CVE-2025-31947
Mattermost Windows
5.8
MEDIUM
EPSS
0.4%
2025 CWE-645 1 PoC

Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.

CVE-2025-11427
WP Migrate Lite – Migration Made Easy Web Windows
5.8
MEDIUM
EPSS
0.1%
2025 CWE-918 1 PoC

The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.7.6 via the wpmdb_flush AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to obtain information about internal services.

CVE-2025-43919
Mailman General
5.8
MEDIUM
EPSS
0.2%
2025 CWE-24 2 PoCs

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CVE-2025-43716
LANDesk Management Suite Web Networking
5.8
MEDIUM
EPSS
0.2%
2025 CWE-180 1 PoC

A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the /client/index.php endpoint, an attacker can bypass access controls and gain unauthorized access to various endpoints such as /client/index.php%3F.php/gsb/firewall.php within the management web panel, potentially exposing sensitive device information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2025-27888
Apache Druid Web ⚡ nuclei
5.8
MEDIUM
EPSS
2.6%
2025 CWE-918 0 PoCs

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects all previous Druid versions. When using the Druid management proxy, a request that has a specially crafted URL could be used to redirect the request to an arbitrary server instead. This has the potential for XSS or XSRF. The user is required to be authenticated for this exploit. The management proxy is enabled in Druid's out-of-box con

CVE-2025-49493
CloudTest Cloud ⚡ nuclei
5.8
MEDIUM
EPSS
1.9%
2025 CWE-611 2 PoCs

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

CVE-2025-47872
EG4 12kPV General
5.8
MEDIUM
EPSS
0.1%
2025 CWE-203 1 PoC

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns.

CVE-2025-5921
SureForms Web Windows
5.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.

CVE-2025-8280
Contact Form 7 reCAPTCHA Web Windows
5.8
MEDIUM
EPSS
0.0%
2025 1 PoC

The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.

CVE-2025-9116
WPS Visitor Counter Web Windows
5.8
MEDIUM
EPSS
0.1%
2025 1 PoC

The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.

CVE-2025-47423
Personal Weather Station Dashboard Web ⚡ nuclei
5.8
MEDIUM
EPSS
0.9%
2025 CWE-24 2 PoCs

Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.

CVE-2025-26318
TSplus Remote Access General
5.8
MEDIUM
EPSS
1.7%
2025 CWE-201 1 PoC

hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.

CVE-2025-59797
Profession Fit Web
5.8
MEDIUM
EPSS
0.0%
2025 CWE-425 1 PoC

Profession Fit 5.0.99 Build 44910 allows authorization bypass via a direct request for /api/challenges/{id} and also URLs for eversports, the user-management page, and the plane page.

CVE-2025-13821
Mattermost General
5.7
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560