Base de données CVE
- CVE-2025-48572Élevée7.8
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-34291Élevée8.8
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
- CVE-2025-66644Élevée7.2
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
- CVE-2025-55182Critique10.0
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
- CVE-2025-58487Moyenne4.0
Autorisation incorrecte dans Samsung Account avant la version 15.5.01.1 permet à un attaquant local de lancer une activité arbitraire avec le privilège Samsung Account
- CVE-2025-58486Moyenne4.0
Validation incorrecte des entrées dans Samsung Account avant la version 15.5.01.1 permet à un attaquant local d'exécuter un script arbitraire.
- CVE-2025-62593Élevée8.8
Ray est un moteur de calcul IA. Avant la version 2.52.0, les développeurs utilisant Ray comme outil de développement peuvent être exploités via une vulnérabilité RCE critique exploitable via Firefox et Safari. Cette vulnérabilité est due à une protection insuffisante contre les attaques basées sur navigateur, car la défense actuelle utilise l'en-tête User-Agent commençant par la chaîne "Mozilla" comme mécanisme de défense. Cette défense est insuffisante car la spécification fetch permet de modifier l'en-tête User-Agent. Combinée à une attaque DNS rebinding contre le navigateur, cette vulnérabilité est exploitable contre un développeur exécutant Ray qui visite par inadvertance un site web malveillant, ou à qui une publicité malveillante est diffusée (malvertising). Ce problème a été corrigé dans la version 2.52.0.
- CVE-2025-58360Élevée8.2
GeoServer est un serveur open source qui permet aux utilisateurs de partager et de modifier des données géospatiales. De la version 2.26.0 à avant 2.26.2 et avant 2.25.6, une vulnérabilité XML External Entity (XXE) a été identifiée. L'application accepte une entrée XML via un endpoint spécifique /geoserver/wms opération GetMap. Cependant, cette entrée n'est pas suffisamment assainie ou restreinte, permettant à un attaquant de définir des entités externes dans la requête XML. Ce problème a été corrigé dans GeoServer 2.25.6, GeoServer 2.26.3 et GeoServer 2.27.0.
- CVE-2025-58034Élevée7.2
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
- CVE-2025-13223Élevée8.8
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-64446Critique9.8
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
- CVE-2025-62215Élevée7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-60710Élevée7.8
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
- CVE-2025-12480Critique9.1
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
- CVE-2025-64328Élevée7.2
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.
- CVE-2023-43000Élevée8.8
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
- CVE-2025-21079Élevée7.1
Une validation incorrecte des entrées dans Samsung Members avant la version 5.5.01.3 permet à des attaquants distants de se connecter à une URL arbitraire et de lancer une activité arbitraire avec le privilège Samsung Members. Une interaction de l'utilisateur est requise pour déclencher cette vulnérabilité.
- CVE-2025-11953Critique9.8
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
- CVE-2025-61757Critique9.8
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVE-2025-7851Critique9.8
Un attaquant peut obtenir le shell root sur le système d'exploitation sous-jacent dans des conditions restreintes sur les passerelles Omada.
This product uses the NVD API but is not endorsed or certified by the NVD.