5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-66493
Foxit PDF Editor Web Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

CVE-2025-24243
iOS and iPadOS General
7.8
HIGH
EPSS
0.0%
2025 4 PoCs

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted file may lead to arbitrary code execution.

CVE-2025-50675
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 2 PoCs

GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory is accessible with full read, write, and execute permissions for all users, allowing unprivileged users to manipulate files within the directory, including executable files like GPMAW3.exe, Fragment.exe, and the uninstaller GPsetup64_17028.exe. An attacker with user-level access can exploit this misconfiguration by replacing or modifying the uninstaller (GPsetup64_17028.exe) with a malicious version. While the application itself runs in the user's

CVE-2025-49667
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.8%
2025 CWE-415 1 PoC

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2025-30464
macOS General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVE-2025-24170
macOS General
7.8
HIGH
EPSS
0.1%
2025 1 PoC

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVE-2025-68973
GnuPG General
7.8
HIGH
EPSS
0.0%
2025 CWE-675 2 PoCs

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

CVE-2025-48549
Android General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-63261
Software Genérico Cloud
7.8
HIGH
EPSS
0.1%
2025 1 PoC

AWStats 8.0 is vulnerable to Command Injection via the open function

CVE-2025-21727
Linux General
7.8
HIGH
EPSS
0.0%
2025 3 PoCs

In the Linux kernel, the following vulnerability has been resolved: padata: fix UAF in padata_reorder A bug was found when run ltp test: BUG: KASAN: slab-use-after-free in padata_find_next+0x29/0x1a0 Read of size 4 at addr ffff88bbfe003524 by task kworker/u113:2/3039206 CPU: 0 PID: 3039206 Comm: kworker/u113:2 Kdump: loaded Not tainted 6.6.0+ Workqueue: pdecrypt_parallel padata_parallel_worker Call Trace: <TASK> dump_stack_lvl+0x32/0x50 print_address_description.constprop.0+0x6b/0x3d0 print_report+0xdd/0x2c0 kasan_report+0xa5/0xd0 padata_find_next+0x29/0x1a0 padata_reorder+0x131/0x220 pada

CVE-2025-61156
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL.

CVE-2025-26859
RemoteView PC Application Console General
7.8
HIGH
EPSS
0.0%
2025 CWE-427 1 PoC

RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

CVE-2025-69875
Software Genérico General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local attacker to place files in high-privilege locations, potentially leading to privilege escalation.

CVE-2025-55230
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-822 1 PoC

Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.

CVE-2025-24267
macOS General
7.8
HIGH
EPSS
0.0%
2025 1 PoC

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVE-2025-0478
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2025 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform, altering their behaviour.

CVE-2025-24379
Unity General
7.8
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

CVE-2025-54257
Acrobat Reader General
7.8
HIGH
EPSS
0.0%
2025 CWE-416 1 PoC

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.

CVE-2025-0015
Valhall GPU Kernel Driver General
7.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to make improper GPU processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r48p0 through r49p1, from r50p0 through r52p0; Arm 5th Gen GPU Architecture Kernel Driver: from r48p0 through r49p1, from r50p0 through r52p0.

CVE-2025-66495
Foxit PDF Reader Web Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.