5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-26865
Apache OFBiz Web
3.5
LOW
EPSS
0.4%
2025 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.   It's a regression between 18.12.17 and 18.12.18. In case you use something like that, which is not recommended! For security, only official releases should be used. In other words, if you use 18.12.17 you are still safe. The version 18.12.17 is not a affected. But something between 18.12.17 and 18.12.18 is. In that case, users are recommended to upgrade to version 18.12.18, which fixes the issue.

CVE-2025-3583
Newsletter Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-1624
GDPR Cookie Compliance Web Windows
3.5
LOW
EPSS
0.1%
2025 1 PoC

The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-58409
Graphics DDK General
3.5
LOW
EPSS
0.0%
2025 CWE-119 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory.

CVE-2025-1363
URL Shortener | Conversion Tracking | AB Testing | WooCommerce Web Windows
3.5
LOW
EPSS
0.0%
2025 1 PoC

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-1452
Favorites Web Windows
3.5
LOW
EPSS
0.1%
2025 1 PoC

The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-65228
Software Genérico Web
3.5
LOW
EPSS
0.0%
2025 1 PoC

A stored cross-site scripting vulnerability exists in the web management interface of the R.V.R. Elettronica TLK302T telemetry controller (firmware 1.5.1799).

CVE-2025-10636
NS Maintenance Mode for WP Web Windows
3.5
LOW
EPSS
0.0%
2025 1 PoC

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-6945
GitLab DevOps
3.5
LOW
EPSS
0.0%
2025 CWE-77 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments.

CVE-2025-1525
Ultimate Dashboard Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-22445
Mattermost General
3.5
LOW
EPSS
0.2%
2025 CWE-754 1 PoC

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

CVE-2025-5069
GitLab DevOps
3.5
LOW
EPSS
0.0%
2025 CWE-708 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim's project.

CVE-2025-63292
Software Genérico Windows
3.5
LOW
EPSS
0.0%
2025 2 PoCs

Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM authentication over the `FreeWifi_secure` network. During the EAP-Response/Identity exchange, the subscriber's full Network Access Identifier (NAI), which embeds the raw IMSI, is transmitted without encryption, tunneling, or pseudonymization. An attacker located within Wi-Fi range (~100 meters) can p

CVE-2025-14594
GitLab DevOps Web
3.5
LOW
EPSS
0.0%
2025 CWE-639 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

CVE-2025-3650
jQuery Colorbox Web Windows
3.5
LOW
EPSS
0.0%
2025 1 PoC

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators.

CVE-2025-1523
Ultimate Dashboard Web Windows
3.5
LOW
EPSS
0.2%
2025 1 PoC

The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-55523
Software Genérico Web ⚡ nuclei
3.5
LOW
EPSS
0.3%
2025 0 PoCs

An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.

CVE-2025-10583
WP Fastest Cache Premium Web Windows
3.5
LOW
EPSS
0.0%
2025 CWE-862 2 PoCs

The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.4 via the 'get_server_time_ajax_request' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The free version is not affected.

CVE-2025-65858
Software Genérico Web
3.5
LOW
EPSS
0.0%
2025 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.

CVE-2025-13758
Server General
3.5
LOW
EPSS
0.0%
2025 CWE-200 1 PoC

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.