5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-3415
Grafana DevOps ⚡ nuclei
4.3
MEDIUM
EPSS
0.3%
2025 CWE-200 0 PoCs

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01

CVE-2025-21014
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-5730
Contact Form Plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVE-2025-21055
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

CVE-2025-22828
Apache CloudStack Web Cloud
4.3
MEDIUM
EPSS
18.4%
2025 CWE-200 1 PoC

CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add comments (annotations) to such resources.  An attacker with a user-account and access or prior knowledge of resource UUIDs may exploit this issue to read contents of the comments (annotations) or add malicious comments (annotations) to such resources.  This may cause potential loss of confidentiality of CloudStack environm

CVE-2025-29705
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.

CVE-2025-4690
AngularJS Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-1333 4 PoCs

A regular expression used by AngularJS'  linky https://docs.angularjs.org/api/ngSanitize/filter/linky  filter to detect URLs in input text is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can cause a Regular expression Denial of Service (ReDoS) https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS  attack on the application. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://

CVE-2025-47870
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.

CVE-2025-47813
🔥 KEV Wing FTP Server General ⚡ nuclei
4.3
MEDIUM
EPSS
25.0%
2025 CWE-209 2 PoCs

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CVE-2025-11519
Optimole – Optimize Images in Real Time Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-639 1 PoC

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the /wp-json/optml/v1/move_image REST API endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to offload media that doesn't belong to them.

CVE-2025-2942
Order Delivery Date Web Windows
4.3
MEDIUM
EPSS
0.3%
2025 1 PoC

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

CVE-2025-4476
Software Genérico Web
4.3
MEDIUM
EPSS
0.3%
2025 CWE-476 1 PoC

A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requir

CVE-2025-49192
SICK Field Analytics General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-1021 1 PoC

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while clicking on seemingly innocuous objects.

CVE-2025-21016
Samsung Mobile Devices Web
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allows local attackers to use the privileged APIs.

CVE-2025-11762
HubSpot All-In-One Marketing – Forms, Popups, Live Chat Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract a list of all installed plugins and their versions which can be leveraged for reconnaissance and further attacks.

CVE-2025-1922
Chrome General
4.3
MEDIUM
EPSS
0.3%
2025 CWE-451 1 PoC

Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2025-65647
Software Genérico Web
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.

CVE-2025-36599
PowerFlex Manager VM General
4.3
MEDIUM
EPSS
0.2%
2025 CWE-532 1 PoC

Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.

CVE-2025-1762
Event Tickets with Ticket Scanner Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-20956
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.