Latest CVE Feed
-
6.5
MEDIUMCVE-2024-56427
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds... Read more
- Published: May. 14, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-55569
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-o... Read more
- Published: May. 14, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-32363
mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
4.6
MEDIUMCVE-2025-25370
An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the show app only setting function.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2024-58101
Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. ... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2024-57096
An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.... Read more
Affected Products : wps_office- Published: May. 14, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2024-45516
An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary... Read more
Affected Products : zimbra_collaboration_suite- Published: May. 14, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-4641
Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associa... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: XML External Entity
-
8.3
HIGHCVE-2025-4640
Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevan... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
7.6
HIGHCVE-2025-33104
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
- Published: May. 14, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-2900
IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES... Read more
Affected Products : semeru_runtime- Published: May. 14, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Denial of Service
-
2.0
LOWCVE-2025-0138
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not aff... Read more
Affected Products : prisma_cloud_compute_edition- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-0137
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. Th... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-0136
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall th... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Cryptography
-
5.2
MEDIUMCVE-2025-0135
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and... Read more
- Published: May. 14, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-0134
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.... Read more
Affected Products : cortex_xdr_broker_vm- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-0133
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when t... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-0132
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue.... Read more
Affected Products : cortex_xdr_broker_vm- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-0131
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileg... Read more
Affected Products : metadefender_endpoint_security_sdk- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: May. 14, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Information Disclosure