Base de datos CVE
Archivo de vulnerabilidades conocidas (CVE) con puntuación CVSS, gravedad, productos y fabricantes afectados. Filtra por año y severidad.
- CVE-2025-14174Alta8.8
Acceso a memoria fuera de límites en ANGLE en Google Chrome en Mac anterior a 143.0.7499.110 permitió a un atacante remoto realizar un acceso a memoria fuera de límites mediante una página HTML manipulada. (Severidad de seguridad de Chromium: Alta)
- CVE-2025-8110Alta8.8
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
- CVE-2025-62221Alta7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-59718Crítica9.8
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
- CVE-2025-48633Media5.5
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-48572Alta7.8
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-34291Alta8.8
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
- CVE-2025-66644Alta7.2
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
- CVE-2025-55182Crítica10.0
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
- CVE-2025-58487Media4.0
Autorización indebida en Samsung Account anterior a la versión 15.5.01.1 permite a un atacante local lanzar una actividad arbitraria con privilegio de Samsung Account.
- CVE-2025-58486Media4.0
Validación de entrada incorrecta en Samsung Account anterior a la versión 15.5.01.1 permite a un atacante local ejecutar un script arbitrario.
- CVE-2025-62593Alta8.8
Ray es un motor de computación de IA. Antes de la versión 2.52.0, los desarrolladores que trabajan con Ray como herramienta de desarrollo pueden ser explotados mediante una vulnerabilidad crítica de RCE explotable a través de Firefox y Safari. Esta vulnerabilidad se debe a una protección insuficiente contra ataques basados en navegador, ya que la defensa actual utiliza la cabecera User-Agent que comienza con la cadena "Mozilla" como mecanismo de defensa. Esta defensa es insuficiente ya que la especificación fetch permite modificar la cabecera User-Agent. Combinado con un ataque de DNS rebinding contra el navegador, esta vulnerabilidad es explotable contra un desarrollador que ejecuta Ray y que visita inadvertidamente un sitio web malicioso, o al que se le sirve un anuncio malicioso (malvertising). Este problema ha sido corregido en la versión 2.52.0.
- CVE-2025-58360Alta8.2
GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Desde la versión 2.26.0 hasta antes de la 2.26.2 y antes de la 2.25.6, se identificó una vulnerabilidad XML External Entity (XXE). La aplicación acepta entradas XML a través del endpoint específico /geoserver/wms operación GetMap. Sin embargo, esta entrada no está suficientemente saneada ni restringida, lo que permite a un atacante definir entidades externas dentro de la solicitud XML. Este problema ha sido corregido en GeoServer 2.25.6, GeoServer 2.26.3 y GeoServer 2.27.0.
- CVE-2025-58034Alta7.2
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
- CVE-2025-13223Alta8.8
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-64446Crítica9.8
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
- CVE-2025-62215Alta7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-60710Alta7.8
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
- CVE-2025-12480Crítica9.1
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
- CVE-2025-64328Alta7.2
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.
This product uses the NVD API but is not endorsed or certified by the NVD.