5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-47700
Mattermost General
3.5
LOW
EPSS
0.0%
2025 CWE-918 1 PoC

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions

CVE-2025-9111
AI ChatBot for WordPress Web Windows
3.5
LOW
EPSS
0.1%
2025 1 PoC

The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-25983
Software Genérico General
3.4
LOW
EPSS
0.2%
2025 1 PoC

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.

CVE-2025-22211
JoomShopping component for Joomla Web Database
3.4
LOW
EPSS
0.0%
2025 CWE-89 1 PoC

A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend.

CVE-2025-27889
Wing FTP Server General
3.4
LOW
EPSS
0.2%
2025 CWE-15 2 PoCs

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.

CVE-2025-21023
WcsExtension for Galaxy Watch General
3.3
LOW
EPSS
0.0%
2025 1 PoC

Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.

CVE-2025-0011
AMD Ryzen™ 8000 Series Desktop Processors General
3.3
LOW
EPSS
0.1%
2025 CWE-212 1 PoC

Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in loss of confidentiality.

CVE-2025-55307
Software Genérico Web Windows
3.3
LOW
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds read in internal path-parsing logic, potentially leading to information disclosure or memory corruption.

CVE-2025-23340
NVIDIA CUDA Toolkit General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability may lead to a partial denial of service.

CVE-2025-9324
PDF Reader General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2025-9323
PDF Reader General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2025-9327
PDF Reader General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with othe

CVE-2025-70330
Software Genérico General
3.3
LOW
EPSS
0.0%
2025 1 PoC

Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields at precise offsets within an otherwise valid .EGP file, an attacker can trigger an out-of-bounds memory read during parsing. This results in an unhandled access violation and application crash, leading to a local denial-of-service condition when the crafted file is opened by a user.

CVE-2025-23339
NVIDIA CUDA Toolkit General
3.3
LOW
EPSS
0.0%
2025 CWE-121 1 PoC

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running cuobjdump.

CVE-2025-21022
Galaxy Wearable General
3.3
LOW
EPSS
0.0%
2025 1 PoC

Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.

CVE-2025-21024
Smart View General
3.3
LOW
EPSS
0.0%
2025 1 PoC

Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.

CVE-2025-23338
NVIDIA CUDA Toolkit General
3.3
LOW
EPSS
0.0%
2025 CWE-129 1 PoC

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write by running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.

CVE-2025-20977
Samsung Notes General
3.3
LOW
EPSS
0.1%
2025 1 PoC

Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

CVE-2025-25618
Software Genérico General
3.3
LOW
EPSS
0.1%
2025 1 PoC

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.

CVE-2025-9325
PDF Reader General
3.3
LOW
EPSS
0.0%
2025 CWE-125 1 PoC

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe