5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-30179
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.

CVE-2025-15527
WP Recipe Maker Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 via the api_get_post_summary function due to insufficient restrictions on which posts can be retrieved. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from posts they may not be able to edit or read otherwise. This also affects password protected, private, or draft posts that they should not have access to.

CVE-2025-65796
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

CVE-2025-7000
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2025 CWE-201 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVE-2025-15473
Timetics Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.

CVE-2025-41254
Spring Framework Web
4.3
MEDIUM
EPSS
0.1%
2025 CWE-352 2 PoCs

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: * 6.2.0 - 6.2.11 * 6.1.0 - 6.1.23 * 6.0.x - 6.0.29 * 5.3.0 - 5.3.45 * Older, unsupported versions are also affected. MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix versionAvailability6.2.x6.2.12OSS6.1.x6.1.24 Commercial https://enterprise.spring.io/ 6.0.xN/A Out of support https://spring.io/projects/spring-framework#support 5.3.x5.

CVE-2025-27581
BRICS General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-425 1 PoC

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.

CVE-2025-65799
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

CVE-2025-27455
Endress+Hauser MEAC300-FNADE4 General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others to take control of their computer while clicking on seemingly innocuous objects.

CVE-2025-59687
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization.

CVE-2025-3227
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel.

CVE-2025-2527
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.

CVE-2025-52923
aTrust General
4.3
MEDIUM
EPSS
0.1%
2025 CWE-732 1 PoC

Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.

CVE-2025-27571
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived Channels" configuration when fetching channel metadata of a post from archived channels, which allows authenticated users to access such information when a channel is archived.

CVE-2025-10588
PixelYourSite – Your smart PIXEL (TAG) & API Manager Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 11.1.2. This is due to missing or incorrect nonce validation on the adminEnableGdprAjax() function. This makes it possible for unauthenticated attackers to modify GDPR settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-41443
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint

CVE-2025-9294
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-285 1 PoC

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete quiz results.

CVE-2025-13765
Server General
4.3
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

CVE-2025-4664
Chrome General
4.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2025-6195
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2025 CWE-425 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.