Latest CVE Feed
-
9.2
CRITICALCVE-2025-4638
A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since ver... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
8.7
HIGHCVE-2025-4637
Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file. .This issue affects dlib: before <19.24.7.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-46786
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-46785
Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30668
Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30667
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30666
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30665
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-30664
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-30663
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
-
8.2
HIGHCVE-2025-0130
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Re... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
7.4
HIGHCVE-2025-47710
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-47709
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-47708
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-47707
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-47706
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-47705
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 0.0.0 before 2.0.5.... Read more
Affected Products : iframe_remove_filter- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-47704
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.5.... Read more
Affected Products : klaro_cookie_\&_consent_management- Published: May. 14, 2025
- Modified: Jun. 10, 2025
-
6.1
MEDIUMCVE-2025-47703
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14.... Read more
- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-47702
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Providers allows Cross-Site Scripting (XSS).This issue affects oEmbed Providers: from 0.0.0 before 2.2.2.... Read more
Affected Products : oembed_providers- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting