5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-27847
Software Genérico Web
4.3
MEDIUM
EPSS
0.0%
2025 2 PoCs

In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.

CVE-2025-21030
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.

CVE-2025-49164
VIP1113 Networking
4.3
MEDIUM
EPSS
0.1%
2025 CWE-321 1 PoC

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a485f49a8a7d0c8b0fdc9f51ced50f2530668a.

CVE-2025-8944
OceanWP Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

CVE-2025-2571
Mattermost General
4.2
MEDIUM
EPSS
0.2%
2025 CWE-303 1 PoC

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.

CVE-2025-6197
Grafana DevOps ⚡ nuclei
4.2
MEDIUM
EPSS
0.6%
2025 CWE-601 0 PoCs

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

CVE-2025-56608
Software Genérico Web
4.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cryptographic algorithm known to allow hash collisions. This makes the authentication mechanism vulnerable to replay, spoofing, or brute-force attacks, potentially leading to unauthorized access. The vulnerability corresponds to CWE-327 and aligns with OWASP M5: Insufficient Cryptography and MASVS MSTG-CRYPTO-4.

CVE-2025-49193
Field Analytics Web
4.2
MEDIUM
EPSS
0.3%
2025 CWE-693 1 PoC

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).

CVE-2025-53021
Moodle General
4.2
MEDIUM
EPSS
0.5%
2025 CWE-384 1 PoC

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2025-52357
Software Genérico Web Networking
4.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firmware V2.2.14), allowing an authenticated attacker to execute arbitrary JavaScript code in the context of the router s web interface. The vulnerability is triggered via user-supplied input in the ping form field, which fails to sanitize special characters. This can be exploited to hijack sessions or escalate privileges through social engineering or browser-based attacks.

CVE-2025-3951
WP-Optimize Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.

CVE-2025-1986
Gutentor Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Gutentor WordPress plugin before 3.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2025-43929
kitty General
4.1
MEDIUM
EPSS
0.1%
2025 CWE-346 1 PoC

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

CVE-2025-21037
SamsungNotes General
4.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for triggering this vulnerability.

CVE-2025-8865
YugabyteDB General
4.1
MEDIUM
EPSS
0.0%
2025 CWE-476 1 PoC

The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.

CVE-2025-53905
vim General
4.1
MEDIUM
EPSS
0.0%
2025 CWE-22 1 PoC

Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some st

CVE-2025-2048
Lana Downloads Manager Web Windows
4.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server

CVE-2025-47811
Wing FTP Server General
4.1
MEDIUM
EPSS
0.3%
2025 CWE-267 1 PoC

In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web application itself offers several legitimate ways to execute arbitrary system commands (i.e., through the web console or the task scheduler), and they are automatically executed in the highest possible privilege context. Because administrative users of the web interface are not necessarily also system administrators, one might argue that this is a privilege escalation. (If a privileged application role is not available to an attacker, CVE-2025-47812

CVE-2025-64641
Mattermost General
4.1
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts

CVE-2025-1446
Pods Web Database Windows
4.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks