CVE-2025-65797
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitraril
CVSS
6.5
Medio
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Publicado: 8 dic 2025 · Última mod.: 5 jul 2026 · CWE-284
0.2%EPSS · 30 días0.3%
2026-06-302026-07-19
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-503517.8 ALT84.9%
——25Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.4dCVE-2026-504237.8 ALT82.8%
——25Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.5dCVE-2026-498057.0 ALT81.6%
——24Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.4dCVE-2023-285319.8 CRÍ81.1%
——24ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.6dCVE-2026-393647.5 ALT79.6%
——24Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.5dCVE-2026-212628.8 ALT79.0%
——24Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.9d