5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-53906
vim General
4.1
MEDIUM
EPSS
0.0%
2025 CWE-22 1 PoC

Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some st

CVE-2025-20999
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

CVE-2025-3943
Niagara Framework Windows
4.1
MEDIUM
EPSS
0.4%
2025 CWE-598 1 PoC

Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-4573
Mattermost Web Windows
4.1
MEDIUM
EPSS
0.2%
2025 CWE-90 1 PoC

Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT /api/v4/ldap/groups/{remote_id}/link API when objectGUID is configured as the Group ID Attribute.

CVE-2025-13001
donation Web Database Windows
4.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such as admin to perform SQL injection attacks

CVE-2025-20886
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.

CVE-2025-20896
EasySetup General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information.

CVE-2025-55631
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion. NOTE: the Supplier reports that the system-wide limit is intentional.

CVE-2025-20899
PushNotification General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in PushNotification prior to version 13.0.00.15 in Android 12, 14.0.00.7 in Android 13, and 15.1.00.5 in Android 14 allows local attackers to access sensitive information.

CVE-2025-0239
Firefox General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVE-2025-32364
Poppler General
4.0
MEDIUM
EPSS
0.1%
2025 CWE-190 1 PoC

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

CVE-2025-20990
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.

CVE-2025-21067
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

CVE-2025-20992
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.

CVE-2025-21054
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

CVE-2025-8285
Mattermost Confluence Plugin Web
4.0
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.

CVE-2025-21052
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

CVE-2025-50072
Oracle WebLogic Server Database
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 4.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U

CVE-2025-21066
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

CVE-2025-32056
Infotainment system ECU General
4.0
MEDIUM
EPSS
0.0%
2025 CWE-1241 2 PoCs

The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head unit. It is possible to reveal all 32 corresponding responses by sniffing CAN traffic or by pre-calculating the values, which allow to bypass the protection. First identified on Nissan Leaf ZE1 manufactured in 2020.