5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-55314
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

CVE-2025-53419
COMMGR General
7.8
HIGH
EPSS
0.0%
2025 CWE-94 1 PoC

Delta Electronics COMMGR has Code Injection vulnerability.

CVE-2025-25179
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.

CVE-2025-24864
RemoteView Agent (for Windows) Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-276 1 PoC

Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.

CVE-2025-56124
Software Genérico General
7.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

CVE-2025-24228
macOS General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to execute arbitrary code with kernel privileges.

CVE-2025-25178
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2025 CWE-1284 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.

CVE-2025-53773
Microsoft Visual Studio 2022 version 17.14 General
7.8
HIGH
EPSS
4.6%
2025 CWE-77 2 PoCs

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

CVE-2025-51006
Software Genérico General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a specifically crafted pcap file to the tcprewrite binary, a local attacker can exploit this flaw to cause a Denial of Service (DoS) via memory corruption.

CVE-2025-57227
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via placing a crafted executable file into a parent folder.

CVE-2025-53841
Guardicore Platform Agent Windows
7.8
HIGH
EPSS
0.0%
2025 CWE-829 1 PoC

The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows users have default write access to. This allows an unprivileged local user to create a crafted "openssl.cnf" file in that location and, by specifying the path to a custom DLL file in a custom OpenSSL engine definition, execute arbitrary commands with the privileges of the Guardicore

CVE-2025-24277
macOS General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVE-2025-24380
Unity General
7.8
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

CVE-2025-63261
Software Genérico Cloud
7.8
HIGH
EPSS
0.1%
2025 1 PoC

AWStats 8.0 is vulnerable to Command Injection via the open function

CVE-2025-24173
iOS and iPadOS General
7.8
HIGH
EPSS
0.0%
2025 4 PoCs

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.

CVE-2025-0289
Migrate OS to SSD General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.

CVE-2025-6087
Software Genérico Web Cloud
7.8
HIGH
EPSS
0.5%
2025 CWE-918 4 PoCs

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This issue allowed attackers to load remote resources from arbitrary hosts under the victim site’s domain for any site deployed using the Cloudflare adapter for Open Next.  For example: https://victim-site.com/_next/image?url=https://attacker.com In this example, attacker-controlled conten

CVE-2025-24213
Safari General
7.8
HIGH
EPSS
0.0%
2025 2 PoCs

This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory corruption.

CVE-2025-6020
Software Genérico General
7.8
HIGH
EPSS
0.1%
2025 CWE-22 1 PoC

A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.