5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-20923
Galaxy Wearable General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege.

CVE-2025-26417
Android General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-20993
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2025-20962
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

CVE-2025-23022
FreeType General
4.0
MEDIUM
EPSS
0.0%
2025 CWE-190 1 PoC

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

CVE-2025-21003
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-20980
libsavscmn General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

CVE-2025-54310
qBittorrent General
4.0
MEDIUM
EPSS
0.1%
2025 CWE-669 1 PoC

qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.

CVE-2025-21029
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.

CVE-2025-44001
Mattermost Confluence Plugin Web
4.0
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.

CVE-2025-20991
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.

CVE-2025-1939
Firefox General
3.9
LOW
EPSS
0.1%
2025 1 PoC

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.

CVE-2025-13326
Mattermost General
3.9
LOW
EPSS
0.0%
2025 CWE-693 1 PoC

Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.

CVE-2025-53971
Mattermost Web
3.8
LOW
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.

CVE-2025-22449
Mattermost General
3.8
LOW
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

CVE-2025-6943
Secret Server Database
3.8
LOW
EPSS
0.1%
2025 CWE-269 1 PoC

Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.

CVE-2025-8594
Pz-LinkCard Web Windows
3.8
LOW
EPSS
0.0%
2025 1 PoC

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

CVE-2025-14573
Mattermost Web
3.8
LOW
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561

CVE-2025-58578
Enterprise Analytics Web
3.8
LOW
EPSS
0.1%
2025 CWE-770 1 PoC

A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.

CVE-2025-25228
Virtuemart component for Joomla Web Database
3.8
LOW
EPSS
0.2%
2025 CWE-89 1 PoC

A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.