Latest CVE Feed
-
6.5
MEDIUMCVE-2025-30668
Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30667
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30666
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30665
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-30664
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-30663
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
-
8.2
HIGHCVE-2025-0130
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Re... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
7.4
HIGHCVE-2025-47710
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-47709
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-47708
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-47707
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-47706
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-47705
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 0.0.0 before 2.0.5.... Read more
Affected Products : iframe_remove_filter- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-47704
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.5.... Read more
Affected Products : klaro_cookie_\&_consent_management- Published: May. 14, 2025
- Modified: Jun. 10, 2025
-
6.1
MEDIUMCVE-2025-47703
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14.... Read more
- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-47702
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Providers allows Cross-Site Scripting (XSS).This issue affects oEmbed Providers: from 0.0.0 before 2.2.2.... Read more
Affected Products : oembed_providers- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-47701
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from 0.0.0 before 1.3.0.... Read more
Affected Products : restrict_route_by_ip- Published: May. 14, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-44186
SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.... Read more
Affected Products : best_employee_management_system- Published: May. 14, 2025
- Modified: May. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2025-44184
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.... Read more
Affected Products : best_employee_management_system- Published: May. 14, 2025
- Modified: May. 28, 2025
-
7.2
HIGHCVE-2025-40595
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.... Read more
Affected Products : sma1000_firmware- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Server-Side Request Forgery