5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-22388
Software Genérico Web
5.7
MEDIUM
EPSS
0.5%
2025 CWE-79 1 PoC

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising user data, escalating privileges, or executing unauthorized actions. The issue exists in multiple areas, including content editing, link management, and file uploads.

CVE-2025-21021
Blockchain Keystore General
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-55194
Part-DB-server General
5.7
MEDIUM
EPSS
0.0%
2025 CWE-248 1 PoC

Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.

CVE-2025-1035
KLog Server General ⚡ nuclei
5.7
MEDIUM
EPSS
67.7%
2025 CWE-22 0 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.

CVE-2025-3886
SDP Client General
5.7
MEDIUM
EPSS
0.1%
2025 CWE-362 1 PoC

An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.

CVE-2025-63226
Software Genérico General
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint and add new users without any authentication. This allows attackers to gain unauthorized access to the system and perform malicious activities.

CVE-2025-46710
Graphics DDK General
5.7
MEDIUM
EPSS
0.1%
2025 CWE-416 1 PoC

Possible kernel exceptions caused by reading and writing kernel heap data after free.

CVE-2025-21020
Blockchain Keystore General
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-21044
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2025-52294
Software Genérico General
5.7
MEDIUM
EPSS
0.1%
2025 1 PoC

Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view the wallet balance.

CVE-2025-22936
Software Genérico Networking
5.7
MEDIUM
EPSS
0.1%
2025 1 PoC

An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers.

CVE-2025-13821
Mattermost General
5.7
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560

CVE-2025-2598
Cloud Development Kit Command Line Interface Cloud
5.7
MEDIUM
EPSS
0.1%
2025 CWE-497 1 PoC

When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should upgrade to version 2.178.2 or later and ensure any forked or derivative code is patched to incorporate the new fixes.

CVE-2025-63952
Software Genérico Web
5.7
MEDIUM
EPSS
0.0%
2025 1 PoC

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

CVE-2025-32875
Software Genérico General
5.7
MEDIUM
EPSS
0.0%
2025 3 PoCs

An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any data transmitted via BLE remains unencrypted, allowing attackers within Bluetooth range to eavesdrop on the communication. Furthermore, even if a user manually initiates pairing and bonding in the Android settings, the application continues to transmit data without requiring the watch to be bonded. This fallback behavior enables attackers to exploit the commu

CVE-2025-48172
CHMLib General
5.6
MEDIUM
EPSS
0.1%
2025 CWE-190 1 PoC

CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.

CVE-2025-1461
Vuetify Web
5.6
MEDIUM
EPSS
0.2%
2025 CWE-79 4 PoCs

Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsanitized HTML to be inserted into the page. This can lead to a  Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss  attack. The vulnerability occurs because the default Vuetify translator will return the translation key as the translation, if it can't find an actual translation. This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0. Note: Version 2.x of Vuetify is End-of-Life and will not receive any updates to address thi

CVE-2025-9115
Etsy Shop Web Windows
5.6
MEDIUM
EPSS
0.0%
2025 1 PoC

The Etsy Shop WordPress plugin before 3.0.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.

CVE-2025-1055
K7 Security Anti-Malware General
5.6
MEDIUM
EPSS
0.0%
2025 CWE-862 2 PoCs

A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating system. This flaw stems from missing access control in the driver's IOCTL handler, enabling unprivileged users to perform privileged actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical services or privileged applications.

CVE-2025-27636
Apache Camel Web
5.6
MEDIUM
EPSS
32.4%
2025 3 PoCs

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases. This vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can alter the behaviours such as the camel-bean component, to call another method on the bean, than was