Latest CVE Feed
-
7.1
HIGHCVE-2025-0131
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileg... Read more
Affected Products : metadefender_endpoint_security_sdk- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: May. 14, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-4639
CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: XML External Entity
-
9.2
CRITICALCVE-2025-4638
A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since ver... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
8.7
HIGHCVE-2025-4637
Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file. .This issue affects dlib: before <19.24.7.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-46786
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-46785
Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30668
Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30667
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30666
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-30665
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: May. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-30664
Improper neutralization of special elements in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-30663
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
-
8.2
HIGHCVE-2025-0130
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Re... Read more
Affected Products : pan-os- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
7.4
HIGHCVE-2025-47710
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-47709
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-47708
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-47707
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-47706
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.... Read more
Affected Products : miniorange_2fa- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-47705
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 0.0.0 before 2.0.5.... Read more
Affected Products : iframe_remove_filter- Published: May. 14, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting