5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-8889
Compress & Upload Web Windows
3.8
LOW
EPSS
0.0%
2025 2 PoCs

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2025-6942
Secret Server General
3.8
LOW
EPSS
0.1%
2025 CWE-639 1 PoC

The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to impersonate another distributed engine.

CVE-2025-46094
LiquidFiles General
3.8
LOW
EPSS
0.2%
2025 CWE-24 1 PoC

LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.

CVE-2025-51586
Software Genérico Web ⚡ nuclei
3.7
LOW
EPSS
1.1%
2025 2 PoCs

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

CVE-2025-14592
GitLab DevOps Web
3.7
LOW
EPSS
0.0%
2025 CWE-862 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

CVE-2025-50065
Oracle GraalVM for JDK Web Database
3.7
LOW
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version that is affected is Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2025-54352
WordPress Web Windows
3.7
LOW
EPSS
0.1%
2025 CWE-669 3 PoCs

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

CVE-2025-11244
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content Web Windows
3.7
LOW
EPSS
0.0%
2025 CWE-285 1 PoC

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the `pp_get_ip_address()` function when the "Use transients" feature is enabled. This makes it possible for attackers to bypass authorization by spoofing these headers with the IP address of a legitimately authenticated user, granted the "Use transients" option is enabled (non-default

CVE-2025-53857
Mattermost Confluence Plugin Web
3.7
LOW
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.

CVE-2025-51591
Software Genérico General
3.7
LOW
EPSS
0.4%
2025 2 PoCs

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilities. Using the ‘--sandbox’ option or ‘pandoc-server’ can mitigate such vulnerabilities. Using pandoc with an external ‘--pdf-engine’ can also enable SSRF vulnerabilities, such as CVE-2022-35583 in wkhtmltopdf.

CVE-2025-13324
Mattermost General
3.7
LOW
EPSS
0.1%
2025 CWE-863 1 PoC

Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed.

CVE-2025-8556
Software Genérico Windows
3.7
LOW
EPSS
0.0%
2025 CWE-1287 1 PoC

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

CVE-2025-32421
next.js Networking
3.7
LOW
EPSS
0.4%
2025 CWE-362 3 PoCs

Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-condition vulnerability. This issue only affects the Pages Router under certain misconfigurations, causing normal endpoints to serve `pageProps` data instead of standard HTML. This issue was patched in versions 15.1.6 and 14.2.24 by stripping the `x-now-route-matches` header from incoming requests. Applications hosted on Vercel's platform are not affected by this issue, as the platform does not cache responses based solely on `200 OK` status without explicit `cache-control` h

CVE-2025-30752
Oracle Java SE Database
3.7
LOW
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle Java SE: 24.0.1; Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK. Note: This vulnerability applies to Java deployments, ty

CVE-2025-32943
Software Genérico General
3.7
LOW
EPSS
0.1%
2025 CWE-22 1 PoC

The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server due to a path traversal in the HLS endpoint.

CVE-2025-32471
SICK FLX3-CPUC200 General
3.7
LOW
EPSS
0.3%
2025 CWE-1391 1 PoC

The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.

CVE-2025-49221
Mattermost Confluence Plugin Web
3.7
LOW
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.

CVE-2025-61984
OpenSSH Networking
3.6
LOW
EPSS
0.0%
2025 CWE-159 7 PoCs

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

CVE-2025-2528
Remote Desktop Manager Windows
3.6
LOW
EPSS
0.1%
2025 CWE-285 1 PoC

Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.