5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-46550
yeswiki Web ⚡ nuclei
4.3
MEDIUM
EPSS
0.4%
2025 CWE-79 0 PoCs

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.

CVE-2025-8577
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-59463
TLOC100-100 all Firmware versions General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-833 1 PoC

An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.

CVE-2025-1923
Chrome General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

CVE-2025-2404
STOYS Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS).This issue affects STOYS: from 2 before 20250916.

CVE-2025-9479
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-125 1 PoC

Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2025-8595
Zakra Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings.

CVE-2025-9914
Baggage Analytics General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-288 1 PoC

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.

CVE-2025-62190
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link

CVE-2025-12377
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Author-level access and above, to perform multiple actions, such as removing images from arbitrary galleries. The vulnerability was partially patched in version 1.12.0.

CVE-2025-20129
Cisco SocialMiner Web Networking
4.3
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting

CVE-2025-50340
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized to use the specified sender identity, resulting in unauthorized message delivery as another user. This can lead to impersonation, phishing, or unauthorized communication within the system. NOTE: this is disputed by the Supplier because the only effective way to prevent this sender

CVE-2025-14371
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to add or remove taxonomy terms (tags, categories) on any post, including ones they do not own.

CVE-2025-25274
Mattermost General
4.3
MEDIUM
EPSS
0.5%
2025 CWE-863 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.

CVE-2025-10700
Ally – Web Accessibility & Usability Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable unfiltered file upload and add svg files to the upload list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-10158
rsync General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-129 1 PoC

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

CVE-2025-1711
Endress+Hauser MEAC300-FNADE4 General
4.3
MEDIUM
EPSS
0.3%
2025 CWE-1392 1 PoC

Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.

CVE-2025-8682
Newsup Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the ansar-import plugin.

CVE-2025-10476
WP Fastest Cache – WordPress Cache Plugin Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.

CVE-2025-12443
Chrome General
4.3
MEDIUM
EPSS
0.0%
2025 CWE-125 1 PoC

Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)