Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

CVE ID Publicado Severidad CVSS Descripción
CVE-2025-54585 2025-07-30 N/A 0.0 GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can…
CVE-2025-8331 2025-07-30 HIGH 7.3 A vulnerability was found in code-projects Online Farm System 1.0 and classified as critical. This issue affects some unknown processing…
CVE-2025-8330 2025-07-30 HIGH 7.3 A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. This vulnerability affects unknown code of…
CVE-2025-54584 2025-07-30 N/A 0.0 GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19.1 and below,…
CVE-2025-54583 2025-07-30 N/A 0.0 GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow…
CVE-2025-54581 2025-07-30 HIGH 7.5 vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-controlled HTTP Proxy-Authorization…
CVE-2025-54576 2025-07-30 CRITICAL 9.1 OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into…
CVE-2025-54575 2025-07-30 MEDIUM 5.3 ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing…
CVE-2025-53022 2025-07-30 HIGH 8.6 TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a…
CVE-2025-52187 2025-07-30 HIGH 8.2 GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php.
CVE-2025-51954 2025-07-30 MEDIUM 6.1 playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2024-48916 2025-07-30 HIGH 8.1 Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send…
CVE-2025-8329 2025-07-30 HIGH 7.3 A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of…
CVE-2025-51951 2025-07-30 MEDIUM 6.1 andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2025-50777 2025-07-30 HIGH 7.8 The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access…
CVE-2025-50464 2025-07-30 MEDIUM 6.5 A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to…
CVE-2025-36609 2025-07-30 LOW 2.5 Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with…
CVE-2025-36608 2025-07-30 MEDIUM 6.5 Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low…
CVE-2025-30103 2025-07-30 MEDIUM 5.5 Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Parties vulnerability. A low…
CVE-2025-54829 2025-07-31 N/A 0.0 Rejected reason: Not used
CVE-2025-54828 2025-07-31 N/A 0.0 Rejected reason: Not used
CVE-2025-54827 2025-07-31 N/A 0.0 Rejected reason: Not used
CVE-2025-54826 2025-07-31 N/A 0.0 Rejected reason: Not used
CVE-2025-54825 2025-07-31 N/A 0.0 Rejected reason: Not used
CVE-2025-54824 2025-07-31 N/A 0.0 Rejected reason: Not used
CVE-2025-54823 2025-07-31 N/A 0.0 Rejected reason: Not used
CVE-2023-41674 2025-07-31 N/A 0.0 Rejected reason: Not used
CVE-2025-7356 2025-07-30 N/A 0.0 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-11478 2025-07-30 N/A 0.0 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-54582 2025-07-30 N/A 0.0 Rejected reason: Reason: This candidate was issued in error. Valid Netty requests are issued via https://github.com/netty/netty.
CVE-2025-24119 2025-07-30 HIGH 7.8 This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.7, macOS…
CVE-2025-45620 2025-07-30 HIGH 8.1 An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
CVE-2025-45619 2025-07-30 MEDIUM 6.5 An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function
CVE-2025-43250 2025-07-30 MEDIUM 4.0 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7,…
CVE-2025-25692 2025-07-30 MEDIUM 6.5 A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted…
CVE-2025-25691 2025-07-30 MEDIUM 6.5 A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted…
CVE-2024-45955 2025-07-30 HIGH 7.3 Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
CVE-2024-45515 2025-07-30 MEDIUM 6.1 An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due…
CVE-2025-8328 2025-07-30 HIGH 7.3 A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by this issue…
CVE-2025-8327 2025-07-30 HIGH 7.3 A vulnerability classified as critical was found in code-projects Exam Form Submission 1.0. Affected by this vulnerability is an unknown…
CVE-2025-54656 2025-07-30 MEDIUM 6.5 ** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras:…
CVE-2025-43275 2025-07-30 CRITICAL 9.8 A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS…
CVE-2025-43266 2025-07-30 MEDIUM 5.1 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS…
CVE-2025-43259 2025-07-30 MEDIUM 4.6 This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma…
CVE-2025-43253 2025-07-30 CRITICAL 9.8 This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A…
CVE-2025-43252 2025-07-30 MEDIUM 6.5 This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.6.…
CVE-2025-43249 2025-07-30 HIGH 7.8 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS…
CVE-2025-43245 2025-07-30 CRITICAL 9.8 A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7,…
CVE-2025-43244 2025-07-30 CRITICAL 9.8 A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7,…
CVE-2025-43234 2025-07-30 CRITICAL 9.8 Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in watchOS 11.6, iOS 18.6 and…