Latest CVE Feed
-
6.5
MEDIUMCVE-2025-30665
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-30664
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-30663
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
-
8.2
HIGHCVE-2025-0130
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Re... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
7.4
HIGHCVE-2025-47710
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-47709
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-47708
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-47707
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-47706
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-47705
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 0.0.0 before 2.0.5.... Read more
Affected Products : iframe_remove_filter- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-47704
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.5.... Read more
Affected Products : klaro_cookie_\&_consent_management- Published: May. 14, 2025
- Modified: Jun. 10, 2025
-
6.1
MEDIUMCVE-2025-47703
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14.... Read more
- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-47702
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Providers allows Cross-Site Scripting (XSS).This issue affects oEmbed Providers: from 0.0.0 before 2.2.2.... Read more
Affected Products : oembed_providers- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-47701
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from 0.0.0 before 1.3.0.... Read more
Affected Products : restrict_route_by_ip- Published: May. 14, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-44186
SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.... Read more
Affected Products : best_employee_management_system- Published: May. 14, 2025
- Modified: May. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2025-44184
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.... Read more
Affected Products : best_employee_management_system- Published: May. 14, 2025
- Modified: May. 28, 2025
-
7.2
HIGHCVE-2025-40595
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.... Read more
Affected Products : sma1000_firmware- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-3932
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been... Read more
Affected Products : thunderbird- Published: May. 14, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-3909
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may ... Read more
Affected Products : thunderbird- Published: May. 14, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-3875
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats [email protected] as the ... Read more
Affected Products : thunderbird- Published: May. 14, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication